PT-2024-31212 · Unknown · Titan Sftp+1

Mounir Aarab

·

Published

2024-09-13

·

Updated

2024-09-13

·

CVE-2024-44685

CVSS v3.1

5.0

Medium

VectorAV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Titan SFTP and Titan MFT Server versions 2.0.25.2426 and earlier
Description The issue concerns the exposure of sensitive information, including passwords, in clear text within the JSON response when configuring SMTP settings via the Web UI. This sensitive information exposure occurs in Titan SFTP and Titan MFT Server.
Recommendations For versions 2.0.25.2426 and earlier, consider restricting access to the Web UI until a fix is available, and avoid configuring SMTP settings via the Web UI to minimize the risk of sensitive information exposure.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-44685

Affected Products

Titan Ftp Server
Titan Sftp