Page 1 of 1

Is Core FTP Server vulnerable to the new regreSSHion RCE?

Posted: Thu Jul 04, 2024 4:17 pm
by tomr
If so, is there a timeline for a patch to Core FTP Server?

Although it hasn't yet been exploited on Windows, it is considered a likely possibility. Beyond the usual network-level protections, what other Core FTP Server configurations might be helpful in mitigating an attack? Based on the Kaspersky exploitation write-up linked below, it sounds like connection limits and session timeouts might be effective.

Thanks!

Re: Is Core FTP Server vulnerable to the new regreSSHion RCE?

Posted: Wed Sep 18, 2024 2:33 am
by ForumAdmin
This seems to only apply to Linux. Wouldn't be concerned until it is replicated in Windows.


CVE-2024-6387