CVE-2024-4040 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 99.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2024-05-01.
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.54% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-1336 |
| On CISA KEV | yes — remediate by 2024-05-01 |
| Public exploit | none known |
| Published | 2024-04-22 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | CrushFTP VFS Sandbox Escape Vulnerability |
|---|---|
| Added | 2024-04-24 |
| Due | 2024-05-01 |
| Vendor / product | CrushFTP / CrushFTP |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| crushftp | crushftp |
References
- https://github.com/airbus-cert/CVE-2024-4040
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update
- https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/
- https://github.com/airbus-cert/CVE-2024-4040
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update
- https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4040
→ the Explorer · watch your stack · NVD