Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add module for CrushFTP RCE CVE-2023-43177 #18814

Closed
ccondon-r7 opened this issue Feb 10, 2024 · 1 comment
Closed

Add module for CrushFTP RCE CVE-2023-43177 #18814

ccondon-r7 opened this issue Feb 10, 2024 · 1 comment
Assignees
Labels
suggestion-module New module suggestions

Comments

@ccondon-r7
Copy link
Contributor

Summary

This vulnerability was disclosed in November 2023 by Converge Software and affects a file transfer product with what seems like a reasonably large internet-facing attack surface area (10K+ at time of disclosure according to the company who discovered it, though we haven't verified that ourselves).

Basic example

Code available. See these links:
https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/
https://www.bleepingcomputer.com/news/security/exploit-for-crushftp-rce-chain-released-patch-now/

Motivation

File transfer products have been under widespread attack by financially motivated threat actors the past few years. I'm not familiar with CrushFTP specifically, but even if the public attack surface area was only a quarter of what the researchers claimed it was, that'd still be higher than MOVEit Transfer exposure was when Cl0p started hitting CVE-2023-34362.

@ccondon-r7 ccondon-r7 added the suggestion-module New module suggestions label Feb 10, 2024
@cdelafuente-r7 cdelafuente-r7 self-assigned this Feb 16, 2024
@cdelafuente-r7
Copy link
Contributor

Closing it since it has been implemented: #18918

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
suggestion-module New module suggestions
Projects
Archived in project
Development

No branches or pull requests

2 participants