CVE-2024-53552: Critical severity CrushFTP CrushFTP 10 vulnerability
Published Dec 10, 2024
·Updated
CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.
Affected Software
4 affected components
CrushFTP CrushFTP 10<10.8.3
CrushFTP CrushFTP 11<11.2.3
CrushFTP CrushFTP>=10.0.0<10.8.3
CrushFTP CrushFTP>=11.0.0<11.2.3
Event History
Dec 10, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-53552?
CVE-2024-53552 is rated as a high severity vulnerability due to its potential for account takeover.
2
How do I fix CVE-2024-53552?
To fix CVE-2024-53552, update CrushFTP to version 10.8.3 or later for CrushFTP 10, and to version 11.2.3 or later for CrushFTP 11.
3
What systems are affected by CVE-2024-53552?
CVE-2024-53552 affects CrushFTP version 10 before 10.8.3 and version 11 before 11.2.3.
4
What kind of vulnerability is CVE-2024-53552?
CVE-2024-53552 is a security vulnerability related to mishandling password resets.
5
What could happen if CVE-2024-53552 is exploited?
If exploited, CVE-2024-53552 could lead to unauthorized access and account takeover.