---
title: "Pharos software is NOT susceptible to the new WS_FTP Vulnerability - October 2023"
slug: "pharos-software-is-not-susceptible-to-the-new-ws-ftp-vulnerability"
updated: 2024-04-05T06:37:17Z
published: 2024-04-05T06:37:17Z
canonical: "kb.pharos.com/pharos-software-is-not-susceptible-to-the-new-ws-ftp-vulnerability"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://kb.pharos.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Pharos software is NOT susceptible to the new WS_FTP Vulnerability - October 2023

**Background**

Recently, 8 security vulnerabilities were discovered inside the WS_FTP tool developed by Progress Software:

| CVE | Description | NVD CVSSv3 Score |
| --- | --- | --- |
| [CVE-2023-40044](https://nvd.nist.gov/vuln/detail/CVE-2023-40044) | WS_FTP.NET Deserialization Vulnerability in Ad Hoc Transfer Module | 8.8 |
| [CVE-2023-42657](https://nvd.nist.gov/vuln/detail/CVE-2023-42657) | WS_FTP Directory Traversal Vulnerability | 9.6 |
| [CVE-2023-40045](https://nvd.nist.gov/vuln/detail/CVE-2023-40045) | WS_FTP Reflected Cross-Site Scripting (XSS) Vulnerability | 6.1 |
| [CVE-2023-40046](https://nvd.nist.gov/vuln/detail/CVE-2023-40046) | WS_FTP SQL Injection Vulnerability | 7.2 |
| [CVE-2023-40047](https://nvd.nist.gov/vuln/detail/CVE-2023-40047) | WS_FTP Stored XSS Vulnerability | 4.8 |
| [CVE-2023-40048](https://nvd.nist.gov/vuln/detail/CVE-2023-40048) | WS_FTP Cross-Site Request Forgery Vulnerability | 6.5 |
| [CVE-2022-27665](https://nvd.nist.gov/vuln/detail/CVE-2022-27665) | WS_FTP Reflected XSS Vulnerability | 6.1 |
| [CVE-2023-40049](https://nvd.nist.gov/vuln/detail/CVE-2023-40049) | WS_FTP Information Disclosure Vulnerability | 5.3 |

Two of these vulnerabilities are rated as "Critical" due to the relative ease of launching a remote execution attack. Patches are currently available from Progress Software for at least some of these issues.

Many organizations, including Pharos customers, are urgently investigating where this tool is used and how to update/repair those instances.

**Pharos Software and WS_FTP**

Pharos has reviewed all our software, 3rd party tools/libraries, internal and cloud infrastructure. Pharos does NOT use the WS_FTP tool anywhere.

## Related

- [Pharos Response to CVE-2021-44790 and CVE-2021-44224 - December 2021](/pharos-response-to-cve-2021-44790-and-cve-2021-44224.md)
- [Pharos Beacon Update: December 2020 Release Notes](/pharos-beacon-update-december-2020-release-notes.md)
- [Pharos Response to PrintNightmare Vulnerability - September 2021](/pharos-response-to-printnightmare-vulnerability.md)
- [Pharos response to OpenSSL 3.x vulnerability - November 2022](/pharos-response-to-openssl-3x-vulnerability.md)
- [When running the "Server Configuration Tool" I recieve an error "The request failed with HTTP status 404: Not Found' for the Tracker Web Service test.](/when-running-the-server-configuration-tool-i-recieve-an-error-the-request-failed-with-http-status-404-not-found-for-the-tracker-web-service-test.md)
