PatchSiren cyber security CVE debrief
CVE-2023-40044 Progress CVE debrief
CVE-2023-40044 is a Progress WS_FTP Server deserialization of untrusted data issue that CISA added to its Known Exploited Vulnerabilities catalog on 2023-10-05. Because it is listed as known exploited and marked for known ransomware campaign use, organizations should treat it as a high-priority remediation item and follow vendor guidance immediately.
- Vendor
- Progress
- Product
- WS_FTP Server
- CVSS
- CRITICAL 10
- CISA KEV
- Listed
- Original CVE published
- 2023-10-05
- Original CVE updated
- 2023-10-05
- Advisory published
- 2023-10-05
- Advisory updated
- 2023-10-05
Who should care
Security teams, server administrators, and incident responders responsible for Progress WS_FTP Server deployments, especially any internet-facing instances or systems supporting file transfer workflows.
Technical summary
The vulnerability is described as a deserialization of untrusted data problem in Progress WS_FTP Server. CISA has flagged it as known exploited, and the KEV entry notes known ransomware campaign use. The available source corpus does not provide version ranges or a detailed impact statement, so defenders should rely on the vendor advisory and CISA guidance for exact remediation steps.
Defensive priority
High priority. Known exploitation plus ransomware-campaign association makes this a rapid-response item for asset owners.
Recommended defensive actions
- Inventory all Progress WS_FTP Server installations and determine which systems are exposed.
- Apply vendor mitigations per Progress instructions as soon as possible.
- If mitigations are unavailable for your deployment, discontinue use of the product until a safe remediation path is available.
- Review CISA KEV requirements and track the 2023-10-26 due date for remediation planning.
- Validate whether any WS_FTP Server hosts show signs of unauthorized activity and preserve logs for investigation.
- Monitor the official CVE, NVD, and vendor advisory pages for updated guidance or affected-version details.
Evidence notes
CISA’s Known Exploited Vulnerabilities catalog lists CVE-2023-40044 for Progress WS_FTP Server with dateAdded 2023-10-05, dueDate 2023-10-26, and notes that known ransomware campaign use is known. The source metadata also points to the Progress community advisory and the NVD record as supporting references.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-40044 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-40044
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-40044 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-40044
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.