CVE-2019-12146: Ipswitch WS_FTP Server
Critical severity, CVSS 9.1. EPSS: 4% chance of exploitation in the next 30 days.
A Directory Traversal issue was discovered in SSHServerAPI.dll in Progress ipswitch WS_FTP Server 2018 before 8.6.1. Attackers have the ability to abuse a flaw in the SCP listener by crafting strings using specific patterns to write files and create directories outside of their authorized directory.
Affected products
- Ipswitch WS_FTP Server: before 8.6.1 (fixed in 8.6.1)
Published 2019-06-11. Last modified 2026-06-17.