CrushFTP is warning customers about a vulnerability (unauthenticated HTTP(S) port access) that could put their systems at risk. The company encourages users to immediately update their servers to protect themselves.

The vulnerability allows attackers to gain unauthorized access to unpatched servers if exposed to the Internet via HTTP(S).
See also: Google Chrome: Fixed serious zero-day vulnerability
“versions CrushFTP v11 are affected. (Previous versions are not affected.) CVE will be created soon,” the company warned.
The company explained that an exposed HTTP(S) port could lead to unauthorized access, but the risk is mitigated if CrushFTP's DMZ feature is used.
Although the initial email to customers stated that the vulnerability only affects CrushFTP v11 versions, the advisory issued the same day stated that CrushFTP v10 versions are also.
See also: Hackers exploit Apache Tomcat RCE vulnerability
Customers are urged to immediately apply the latest updates (v11.3.1+). Those who are unable to do so immediately can enable DMZ until security updates are deployed.
According to the Shodan, more than 3,400 CrushFTP instances have their web interface exposed to the internet, meaning they are vulnerable to attacks. It is unclear how many of them have applied the update.

File transfer products like CrushFTP are attractive targets for ransomware gangs and other hackers. This means that users need to stay up to date on new threats and apply the latest security updates in a timely manner.
See also: WP Ghost WordPress: Critical vulnerability puts thousands of sites at risk
Additionally, it is important for organizations using CrushFTP to have appropriate security measures in place, such as firewalls and access controls, to prevent unauthorized access and potential exploitation of vulnerabilities. Regular security audits and assessments to ensure the overall integrity of their systems.
Source: www.bleepingcomputer.com
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
