CVE-2024-9999: Multi-Factor Authentication Bypass in Progress WS_FTP Server
Published Nov 12, 2024
·Updated
In WSFTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
Affected Software
1 affected component
Ipswitch WS_FTP Server<8.8.9
Event History
Nov 12, 2024
CVE Published
via MITRE·04:33 PM
Data Sourced
via MITRE·04:33 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-9999?
CVE-2024-9999 is classified as a high severity vulnerability due to its potential to allow unauthorized access.
2
How do I fix CVE-2024-9999?
To fix CVE-2024-9999, update WS_FTP Server to version 8.8.9 or later.
3
What type of software is affected by CVE-2024-9999?
CVE-2024-9999 affects Ipswitch WS_FTP Server versions prior to 8.8.9.
4
Can CVE-2024-9999 be exploited remotely?
Yes, CVE-2024-9999 can be exploited remotely if the affected software is accessible over the internet.
5
What is the main issue with CVE-2024-9999?
The main issue with CVE-2024-9999 is the incorrect implementation of the authentication algorithm, allowing bypass of two-factor authentication.