CVE-2024-11144
CVE-2024-11144 exposes a critical vulnerability where an FTP server lacks thread safety, enabling remote attackers to crash the service with anomalous data. This denial-of-service condition impacts all users relying on the FTP service for file transfers. Although the SVRS score is 30, indicating a lower immediate risk compared to critical vulnerabilities, the potential for data corruption due to incomplete transfers during a crash should not be ignored. The vulnerability arises because the server is unable to properly manage concurrent requests, leading to crashes when unexpected data is processed. The lack of thread safety (CWE-362) makes the server susceptible to race conditions and other concurrency-related issues. While CVSS assigns a score of 0, highlighting that there is no standard score, the existence of reported instances "In The Wild" suggests active exploitation. This poses a risk that demands immediate attention and patch implementation to prevent service disruptions and potential data integrity compromise.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.