CVE-2017-14035: Critical severity crushftp vulnerability
Published Aug 30, 2017
·Updated
CrushFTP 8.x before 8.2.0 has a serialization vulnerability.
Affected Software
4 affected components
CrushFTP Crushftp=8.0.2
CrushFTP Crushftp=8.0.3
CrushFTP Crushftp=8.0.4
CrushFTP Crushftp=8.1.0
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What versions of CrushFTP are affected by CVE-2017-14035?
CVE-2017-14035 affects CrushFTP versions 8.0.2, 8.0.3, 8.0.4, and 8.1.0.
2
What is the nature of the vulnerability in CVE-2017-14035?
CVE-2017-14035 is a serialization vulnerability in CrushFTP 8.x before 8.2.0.
3
What is the severity of CVE-2017-14035?
CVE-2017-14035 has been classified with a moderate severity level due to the potential for exploitation.
4
How do I fix CVE-2017-14035?
To fix CVE-2017-14035, upgrade to CrushFTP version 8.2.0 or later.
5
What risks are associated with CVE-2017-14035?
Exploitation of CVE-2017-14035 could allow an attacker to manipulate serialized data, leading to remote code execution.