Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-51989 | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover. |
| Link | Providers |
|---|---|
| https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 27 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Crushftp
Crushftp crushftp |
|
| CPEs | cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Crushftp
Crushftp crushftp |
Wed, 11 Dec 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-640 | |
| Metrics |
cvssV3_1
|
Tue, 10 Dec 2024 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CrushFTP 10 before 10.8.3 and 11 before 11.2.3 mishandles password reset, leading to account takeover. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-12-11T15:26:27.063Z
Reserved: 2024-11-20T00:00:00.000Z
Link: CVE-2024-53552
Updated: 2024-12-11T15:26:19.503Z
Status : Analyzed
Published: 2024-12-10T02:15:17.177
Modified: 2025-06-27T17:58:40.553
Link: CVE-2024-53552
No data.
OpenCVE Enrichment
No data.
EUVD