PT-2024-38553 · Ipswitch · Ws Ftp Server
Isira_Adithya
·
Published
2024-08-28
·
Updated
2024-09-04
·
CVE-2024-7745
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
WS FTP Server versions prior to 8.8.8
Description
A missing critical step in the multi-factor authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with
username and password only.Recommendations
For WS FTP Server versions prior to 8.8.8, update to version 8.8.8 or later to resolve the issue. As a temporary workaround, consider disabling the Web Transfer Module until a patch is available. Restrict access to the module to minimize the risk of exploitation. Avoid relying solely on
username and password for authentication until the issue is resolved.Fix
Improper Authentication
Authentication Bypass by Spoofing
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ws Ftp Server