Vulnerability record · CVE-2023-43177 · published 18 November 2023
CVE-2023-43177: CrushFTP object attribute manipulation flaw allows unauthenticated compromise
Crushftp · Crushftp
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-913). A remote, unauthenticated attacker can manipulate object attributes to gain full control of confidentiality, integrity and availability. The flaw was publicly described as a zero-day, so exposure is significant for internet-facing deployments.
Description
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, a public exploit reference and very high EPSS make this an urgent patch-first issue.
What it is
CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-913). A remote, unauthenticated attacker can manipulate object attributes to gain full control of confidentiality, integrity and availability. The flaw was publicly described as a zero-day, so exposure is significant for internet-facing deployments.
Impact
An attacker can read and modify data and disrupt service, with CVSS 3.1 scoring all three impact metrics as High. In practice this means full compromise of the affected CrushFTP instance.
Attack surface
Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed CrushFTP service below 10.5.1 is in scope.
Exploitation
Not listed in CISA KEV, but EPSS is 0.818 (99.6th percentile) and references are tagged Exploit, indicating public exploit material exists and exploitation is likely.
What to do
- Upgrade CrushFTP to 10.5.1 or later immediately.
- If patching cannot be done at once, remove the service from direct internet exposure and restrict access to trusted networks.
- Review CrushFTP logs and configuration for unauthorized changes made before patching.
- Rotate credentials and secrets stored or managed by the CrushFTP instance after remediation.
- Monitor vendor advisories for follow-up fixes or updated guidance.
Detection
- Hunt for unexpected or anomalous requests to CrushFTP endpoints, especially those that alter object or session attributes.
- Alert on CrushFTP process behavior that writes to configuration or user files outside normal administrative activity.
- Correlate CrushFTP access logs with outbound connections or file changes on the host.
- Check for signs of post-exploitation activity such as new accounts, modified permissions or unexpected scheduled tasks.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/ | ExploitThird Party Advisory |
| https://github.com/the-emmons/CVE-Disclosures/blob/main/Pending/CrushFTP-2023-1.md | Third Party Advisory |
| https://convergetp.com/2023/11/16/crushftp-zero-day-cve-2023-43177-discovered/ | ExploitThird Party Advisory |
| https://github.com/the-emmons/CVE-Disclosures/blob/main/Pending/CrushFTP-2023-1.md | Third Party Advisory |
Track CVE-2023-43177 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-43177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.