Описание
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
Уязвимые конфигурации
Конфигурация 1Версия до 8.8.8 (исключая)
cpe:2.3:a:progress:ws_ftp_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 51%
0.00277
Низкий
6.5 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-290
CWE-287
Связанные уязвимости
CVSS3: 6.5
github
больше 1 года назад
In WS_FTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
EPSS
Процентиль: 51%
0.00277
Низкий
6.5 Medium
CVSS3
8.1 High
CVSS3
Дефекты
CWE-290
CWE-287