CVSS 9.8 CRITICAL: crushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account… Known ransomware campaign use. EPSS 100% (100th percentile).
CISA federal remediation date Apr 28 · date passed
CVSS 9.8 CRITICAL: a server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms… EPSS 100% (100th percentile).
CVSS 9 CRITICAL: crushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation… EPSS 95% (100th percentile).
CISA federal remediation date Aug 12 · date passed