CVE-2024-7745: Multi-Factor Authentication Bypass in Progress WS_FTP Server
Published Aug 28, 2024
·Updated
In WSFTP Server versions before 8.8.8 (2022.0.8), a Missing Critical Step in Multi-Factor Authentication of the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
Affected Software
1 affected component
Progress Ws Ftp Server<8.8.8
Event History
Aug 28, 2024
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-7745?
CVE-2024-7745 is rated as a high severity vulnerability due to the potential for unauthorized access.
2
How do I fix CVE-2024-7745?
To fix CVE-2024-7745, upgrade to WS_FTP Server version 8.8.8 or later.
3
What is the impact of CVE-2024-7745 on WS_FTP Server?
CVE-2024-7745 allows attackers to bypass multi-factor authentication and access the system with just a username and password.
4
Which versions of WS_FTP Server are affected by CVE-2024-7745?
CVE-2024-7745 affects all versions of WS_FTP Server prior to 8.8.8.
5
Is multi-factor authentication effective against CVE-2024-7745?
No, CVE-2024-7745 reveals a flaw in the multi-factor authentication implementation that allows users to log in without the second factor.