RaqibCTI
CVE

CVE-2024-4040

P2
CrushFTP VFS Sandbox Escape Vulnerability
CrushFTP · CrushFTP
Date added (CISA)
2024-04-24
Remediation due
2024-05-01
Known ransomware use
Not indicated
Remediation priority
P2past CISA due date

Description

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Source: NVD ↗ · CISA KEV Catalog ↗