• Tenable
  • CVEs
  • Settings
    Links
    Tenable Cloud Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Plugins
  • Overview
  • Plugins Pipeline
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • Tenable Cloud Security Families
  • Tenable Self-Hosted Container Security Families
  • About Plugin Families
  • Release Notes
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
    • Links
    • Tenable Cloud
    • Tenable Community & Support
    • Tenable University
    • Settings
    • Severity
    • Theme
Detections
  • Plugins
  • Overview
  • Plugins Pipeline
  • Release Notes
  • Newest
  • Updated
  • Search
  • Nessus Families
  • WAS Families
  • NNM Families
  • Tenable OT Security Families
  • Tenable Cloud Security Families
  • Tenable Self-Hosted Container Security Families
  • About Plugin Families
  • Audits
  • Overview
  • Newest
  • Updated
  • Search Audit Files
  • Search Items
  • References
  • Authorities
  • Documentation
  • Download All Audit Files
  • Indicators
  • Overview
  • Search
  • Indicators of Attack
  • Indicators of Exposure
  • Release Notes
Analytics
  • CVEs
  • Overview
  • Newest
  • Updated
  • Search
  • Attack Path Techniques
  • Overview
  • Search
  1. CVEs
  2. CVE-2024-9999
  1. CVEs

CVE-2024-9999

medium
  • Information
  • CPEs
  • Plugins

Description

In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

References

https://github.com/Confluenceservice/cve-prioritizer-action

https://github.com/subpop/cve-api

https://github.com/jonhenke/vuln-fixer-tool

https://github.com/rezearcher/x402-cve-triage

https://github.com/Corvalon/lichen

https://github.com/nexorin9/vuln-in-transit-gov

https://github.com/roshk8s/CVEIntel

https://github.com/roshannp/cvefetcher

https://github.com/Addzyyy/cvesieve

https://github.com/PrototypePrime/SCOUT-Security_and_CVE_Outbreak_Universal_Tracker

https://github.com/hawonb711-tech/CVE-Intelligence-Assistant

https://github.com/harshgdev/cve-hunter-mcp

https://github.com/tezgiden/HCLVulnerabilitiesAnalysisTool

https://github.com/grimmolf/redhat-cve-tools

https://github.com/EvgeniyPatlan/cve_diff_scanner

https://github.com/CDThornton23/PDF-Threat-Intelligence-Extraction-Service

https://www.progress.com/ftp-server

https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2024

Details

Source: Mitre, NVD

Published: 2024-11-12

Updated: 2026-04-15

Risk Information

CVSS v2

Base Score: 7.7

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:N

Severity: High

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

Severity: Medium

EPSS

EPSS: 0.00102

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2026 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance