April 23, 2024, 3:26 p.m. | Caitlin Condon

Rapid7 Blog blog.rapid7.com

CVE-2024-4040 is an unauthenticated zero-day vulnerability in managed file transfer software CrushFTP. Successful exploitation allows for arbitrary file read as root, authentication bypass for administrator account access, and remote code execution.

access account account access administrator authentication authentication bypass bypass code code execution compromise crushftp cve cve-2024 emergent threat response exploitation file file transfer managed managed file transfer remote code remote code execution root server software transfer unauthenticated vulnerability vulnerability management zero-day zero-day vulnerability

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

COMM Penetration Tester (PenTest-2), Chantilly, VA OS&CI Job #368

@ Allen Integrated Solutions | Chantilly, Virginia, United States

Consultant Sécurité SI H/F Gouvernance - Risques - Conformité

@ Hifield | Sèvres, France

Infrastructure Consultant

@ Telefonica Tech | Belfast, United Kingdom