CVE-2023-2989

CRITICAL

Globalscape EFT Server < 8.1.0.16 - Out-of-bounds Read in Administration Server

Title source: llm
STIX 2.1

Description

Fortra Globalscape EFT versions before 8.1.0.16 suffer from an out of bounds memory read in their administration server, which can allow an attacker to crash the service or bypass authentication if successfully exploited

Scores

CVSS v3 9.1
EPSS 0.0097
EPSS Percentile 57.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-125
Status published
Products (1)
globalscape/eft_server < 8.1.0.16
Published Jun 22, 2023
Tracked Since Feb 18, 2026