Skip to content
COOEY

EXPOSURES › CVE-2025-47813

CVE-2025-47813

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2026-03-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-47813 ↗
⌖ EXPLOITED IN THE WILD SHAME 45/100 exploited-in-wildinformation-disclosureunpatched

Wing FTP Server exposes sensitive data via UID cookie error messages when misconfigured, enabling information disclosure.

The vulnerability allows attackers to extract sensitive information from error messages when a long UID cookie value is used, creating a significant risk for organizations relying on Wing FTP for secure file transfers. This information disclosure can aid attackers in reconnaissance or credential harvesting, potentially leading to further compromise of FedRAMP or NIST 800-171 systems. DIB organizations must immediately patch or disable the affected server generation to prevent data leakage.

Shame score — The vulnerability is a known information disclosure issue that was actively exploited but does not involve remote code execution or zero-day exploitation.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Wing FTP Server contains a generation of error message containing sensitive information vulnerability when using a long value in the UID cookie.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.