Metrics
Affected Vendors & Products
Tue, 29 Jul 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
ssvc
|
Wed, 23 Jul 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* |
Tue, 22 Jul 2025 17:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
kev
|
Sat, 19 Jul 2025 01:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Sat, 19 Jul 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 18 Jul 2025 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and consequently allows remote attackers to obtain admin access via HTTPS, as exploited in the wild in July 2025. | |
Weaknesses | CWE-420 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-07-18T00:00:00.000Z
Updated: 2025-07-30T01:36:08.877Z
Reserved: 2025-07-18T00:00:00.000Z
Link: CVE-2025-54309

Updated: 2025-07-18T18:41:09.841Z

Status : Analyzed
Published: 2025-07-18T19:15:25.353
Modified: 2025-07-23T17:51:56.027
Link: CVE-2025-54309

No data.