CrushFTP Security Update – 28 April 2024

CrushFTP has released a security update to fix a critical vulnerability in CrushFTP versions below 11.1.

The addressed vulnerability could allow the unauthenticated remote attacker to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the affected system.

CrushFTP Code Execution Vulnerability (CVE-2024-4040):

  • CVSS: 9.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Gain Access

It should be highlighted that CrushFTP is aware that the zero-day vulnerability is being exploited in the wild.

Vulnerabilities

CVE-2024-4040

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

CrushFTP Security Update

References