WS_FTP Security Update – 09 November 2023

WS_FTP has released a security update to address a critical vulnerability affecting WS_FTP Server.

The addressed vulnerability could allow the remote attacker to bypass security restrictions and upload a file to a specified location on the operating system hosting the WS_FTP Server application.

WS_FTP Server Arbitrary File Upload (CVE-2023-42659):

  • CVSS: 9.1
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Consequences: Bypass Security

Affected Versions:

  • WS_FTP Server 2022.0.3 (8.8.3) and earlier.
  • WS_FTP Server 2020.0.5 (8.7.5) and earlier.
Vulnerabilities

CVE-2022-35741

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

WS_FTP Security Advisory

References