Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7745


In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.


Published

2024-08-28T17:15:11.593

Last Modified

2024-09-04T17:57:57.637

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-290
    CWE-304
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application progress ws_ftp_server < 8.8.8 Yes

References