DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.
References

No reference.

History

Fri, 04 Apr 2025 20:30:00 +0000


Fri, 04 Apr 2025 20:00:00 +0000

Type Values Removed Values Added
Description CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass. Remote and unauthenticated HTTP requests to CrushFTP with known usernames can be used to impersonate a user and conduct actions on their behalf, including administrative actions and data retrieval. DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-31161. Reason: This Record is a reservation duplicate of CVE-2025-31161. Notes: All CVE users should reference CVE-2025-31161 instead of this Record. All references and descriptions in this Record have been removed to prevent accidental usage.

Wed, 02 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
References

Tue, 01 Apr 2025 18:30:00 +0000

Type Values Removed Values Added
Description CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access. CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability in the S3 authorization header processing that allows authentication bypass. Remote and unauthenticated HTTP requests to CrushFTP with known usernames can be used to impersonate a user and conduct actions on their behalf, including administrative actions and data retrieval.
References

Fri, 28 Mar 2025 17:45:00 +0000

Type Values Removed Values Added
References

Wed, 26 Mar 2025 17:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Mar 2025 16:00:00 +0000

Type Values Removed Values Added
Description CrushFTP versions 10.0.0 through 10.8.3 and 11.0.0 through 11.3.0 are affected by a vulnerability that may result in unauthenticated access. Remote and unauthenticated HTTP requests to CrushFTP may allow attackers to gain unauthorized access.
Title CrushFTP HTTP Unauthenticated Access
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: REJECTED

Assigner: VulnCheck

Published:

Updated: 2025-04-04T19:48:00.370Z

Reserved: 2025-03-26T15:49:07.306Z

Link: CVE-2025-2825

cve-icon Vulnrichment

Updated: 2025-03-28T17:07:07.312Z

cve-icon NVD

Status : Rejected

Published: 2025-03-26T16:15:23.883

Modified: 2025-04-04T20:15:17.507

Link: CVE-2025-2825

cve-icon Redhat

No data.