{"cvss":10.0,"datePublished":"2023-10-05","dateUpdated":"2023-10-05","description":"Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.","dueDate":"2023-10-26","id":"CVE-2023-40044","kev_catalogs":["cisa"],"knownRansomwareCampaignUse":"Known","notes":"https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023; https://nvd.nist.gov/vuln/detail/CVE-2023-40044","product":"WS_FTP Server","requiredAction":"Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.","severity":"CRITICAL","source":"cisa_known_exploited","title":"Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability","vendor":"Progress"}