WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Patch Now: Critical Vulnerability Exposes CrushFTP Users to Severe Risks  
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Patch Now: Critical Vulnerability Exposes CrushFTP Users to Severe Risks  

Author: ian_41208

Created: Tuesday, November 21, 2023 - 17:40

Categories: Cybersecurity

A critical vulnerability (CVE-2023-43177) in CrushFTP allows hackers to access files, execute code, and steal passwords. Although a fix was issued in version 10.5.2, a recent public exploit by Converge demands immediate updates for CrushFTP users. This exploit lets attackers read, delete files, and potentially gain total control over systems using specific web ports and functions in CrushFTP.

Approximately 10,000 vulnerable instances exist, making them attractive targets for ransomware actors like Clop. Despite patches, the risk persists as attackers may exploit reverse engineered patches. Users must swiftly update their Crust FTP to remain secure.

To effectively mitigate this risk, researchers at Converge recommend the following steps:

  • Update CrushFTP to the latest version.

  • Enable automatic security patch updates.

  • Change the password algorithm to Argon.

  • Audit for unauthorized users and check for recent password changes.

  • Activate the new Limited Server mode for enhanced security.

  • Additional measures that can be implemented to enhance CrushFTP security further include:

  • Using a limited privilege operating system service account for CrushFTP.

  • Deploying Nginx or Apache as a reverse proxy for public-facing servers.

  • Setting firewall rules to limit CrushFTP traffic to trusted IP ranges and hosts.

Read more at Bleeping Computer.

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar