CVE-2023-2989

CRITICAL

Globalscape Eft Server < 8.1.0.16 - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

Scores

CVSS v3 9.1
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-125
Status published
Products (1)
globalscape/eft_server < 8.1.0.16
Published Jun 22, 2023
Tracked Since Feb 18, 2026