Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
CVE's Videos

← Terug naar CVE-database

CVE-2024-4040

CRITICAL · 9.5 CVSS Gepubliceerd: CWE-1336

Beschrijving NL

CrushFTP bevat een niet-gespecificeerde sandbox escape-kwetsbaarheid waarmee een externe aanvaller kan ontsnappen aan het CrushFTP virtuele bestandssysteem (VFS).

Vereiste actie: pas mitigaties toe volgens de instructies van de leverancier of stop het gebruik van het product als mitigaties niet beschikbaar zijn.

Origineel (Engels) tonen

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Vendors

Crushftp

Affected products

Crushftp

References