PT-2024-39990 · Ipswitch · Ws Ftp Server

Isira_Adithya

·

Published

2024-11-12

·

Updated

2026-05-06

·

CVE-2024-9999

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions WS FTP Server versions prior to 8.8.9
Description The issue is related to an incorrect implementation of the authentication algorithm in the Web Transfer Module, allowing users to bypass the second-factor verification and log in using only their username and password.
Recommendations For versions prior to 8.8.9, update to version 8.8.9 or later to resolve the issue. As a temporary workaround, consider restricting access to the Web Transfer Module until the update is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2024-9999

Affected Products

Ws Ftp Server