CVE-2019-12144: Ipswitch WS_FTP Server

Critical severity, CVSS 9.8. EPSS: 2.9% chance of exploitation in the next 30 days.

An issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a path traversal vulnerability using the SCP protocol. Attackers who leverage this flaw could also obtain remote code execution by crafting a payload that abuses the SITE command feature.

Affected products

  • Ipswitch WS_FTP Server: before 8.6.1 (fixed in 8.6.1)

Published 2019-06-11. Last modified 2026-06-17.