Vulnerability Description
Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Globalscape | Eft Server | < 8.1.0.16 |
Related Weaknesses (CWE)
References
- https://kb.globalscape.com/Knowledgebase/11588/Is-EFT-susceptible-to-the-Denial-Vendor Advisory
- https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-gExploitThird Party Advisory
- https://kb.globalscape.com/Knowledgebase/11588/Is-EFT-susceptible-to-the-Denial-Vendor Advisory
- https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-gExploitThird Party Advisory
FAQ
What is CVE-2023-2990?
CVE-2023-2990 is a vulnerability with a CVSS score of 7.5 (HIGH). Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service...
How severe is CVE-2023-2990?
CVE-2023-2990 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2990?
Check the references section above for vendor advisories and patch information. Affected products include: Globalscape Eft Server.