← Vulnerability feed

Vulnerability record · CVE-2023-43177 · published 18 November 2023

CVE-2023-43177: CrushFTP object attribute manipulation flaw allows unauthenticated compromise

Crushftp · Crushftp

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-913). A remote, unauthenticated attacker can manipulate object attributes to gain full control of confidentiality, integrity and availability. The flaw was publicly described as a zero-day, so exposure is significant for internet-facing deployments.

9.8 CVSS 3.1 Critical EPSS 82% · top 0.4% CWE-913 · Improper control of dynamically-managed code
9.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required, a public exploit reference and very high EPSS make this an urgent patch-first issue.

What it is

CrushFTP prior to 10.5.1 is vulnerable to Improperly Controlled Modification of Dynamically-Determined Object Attributes (CWE-913). A remote, unauthenticated attacker can manipulate object attributes to gain full control of confidentiality, integrity and availability. The flaw was publicly described as a zero-day, so exposure is significant for internet-facing deployments.

Impact

An attacker can read and modify data and disrupt service, with CVSS 3.1 scoring all three impact metrics as High. In practice this means full compromise of the affected CrushFTP instance.

Attack surface

Reachable over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. Any internet-exposed CrushFTP service below 10.5.1 is in scope.

Exploitation

Not listed in CISA KEV, but EPSS is 0.818 (99.6th percentile) and references are tagged Exploit, indicating public exploit material exists and exploitation is likely.

What to do

  • Upgrade CrushFTP to 10.5.1 or later immediately.
  • If patching cannot be done at once, remove the service from direct internet exposure and restrict access to trusted networks.
  • Review CrushFTP logs and configuration for unauthorized changes made before patching.
  • Rotate credentials and secrets stored or managed by the CrushFTP instance after remediation.
  • Monitor vendor advisories for follow-up fixes or updated guidance.

Detection

  • Hunt for unexpected or anomalous requests to CrushFTP endpoints, especially those that alter object or session attributes.
  • Alert on CrushFTP process behavior that writes to configuration or user files outside normal administrative activity.
  • Correlate CrushFTP access logs with outbound connections or file changes on the host.
  • Check for signs of post-exploitation activity such as new accounts, modified permissions or unexpected scheduled tasks.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-43177 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2024-4040CrushFTP server-side template injection enables unauthenticated sandbox escape and RCECrushFTP versions before 10.7.1 and 11.1.0 contain a server-side template injection flaw that lets unauthenticated remote attackers escape the VFS sa…KEVEPSS 100%analysed9.8CVE-2025-54309CrushFTP AS2 validation flaw grants remote admin accessCrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 mishandle AS2 validation when the DMZ proxy feature is not in use, letting remote attackers obtain …KEVEPSS 95%analysed9.8CVE-2025-31161CrushFTP AWS4-HMAC auth bypass enables crushadmin takeoverCrushFTP 10 before 10.8.4 and 11 before 11.3.1 contains an authentication bypass in the AWS4-HMAC (S3-compatible) authorization method of its HTTP co…KEVEPSS 100%analysed9.8CVE-2024-53552Crushftp weak password recovery vulnerabilityCrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover.EPSS 0.82%9.8CVE-2017-14035Crushftp deserialization of untrusted data vulnerabilityCrushFTP 8.x before 8.2.0 has a serialization vulnerability.EPSS 1.6%6.1CVE-2025-63419Crushftp cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share files, the feature reflects …EPSS 0.23%6.1CVE-2024-22910Crushftp cross-site scripting vulnerabilityCross Site Scripting (XSS) vulnerability in CrushFTP v.10.6.0 and v.10.5.5 allows an attacker to execute arbitrary code via a crafted payload.EPSS 0.50%6.1CVE-2018-18288Crushftp open redirect vulnerabilityCrushFTP through 8.3.0 is vulnerable to credentials theft via URL redirection.EPSS 0.64%

Source: NIST National Vulnerability Database (record CVE-2023-43177), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.