HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2023-45687

CVSS 8.8v3.1pub. 2023-10-16upd. 2024-11-21

A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id of their choosing

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Southrivertech Titan Mft Server

    APP
    Southrivertech
    < 2.0.18
  • Southrivertech Titan Sftp Server

    APP
    Southrivertech
    < 2.0.18
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2023-45685CRITICAL9.1PL ✓same product

Path traversal przy rozpakowywaniu ZIP w Titan MFT i Titan SFTP Server

CVE-2023-45688MEDIUM4.3same product

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Linux allo...

CVE-2023-45689MEDIUM6.5same product

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows an...

CVE-2023-45690MEDIUM4.9same product

Default file permissions on South River Technologies' Titan MFT and Titan SFTP servers on Linux allows a user ...

CVE-2022-34005CRITICAL9.8PL ✓same vendor

RCE przez zakodowane hasło konta SA w TitanFTP NextGen