PT-2023-29651 · South River Technologies · Titan Sftp+1

Ron Bowes

·

Published

2023-10-16

·

Updated

2024-09-17

·

CVE-2023-45686

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions South River Technologies' Titan MFT and Titan SFTP servers (affected versions not specified)
Description The issue is related to insufficient path validation when writing a file via WebDAV, allowing an authenticated attacker to write a file to any location on the filesystem via path traversal. This affects South River Technologies' Titan MFT and Titan SFTP servers on Linux.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-45686

Affected Products

Titan Mft
Titan Sftp