CVE-2023-45685
16.10.2023, 17:15
Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| southrivertech | titan_mft_server | 𝑥 < 2.0.18 |
| southrivertech | titan_mft_server | 𝑥 < 2.0.18 |
| southrivertech | titan_sftp_server | 𝑥 < 2.0.18 |
| southrivertech | titan_sftp_server | 𝑥 < 2.0.18 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| south_river_technologies | titan_mft | 𝑥 ≤ 2.0.17.2298 | ADP |
| south_river_technologies | titan_sftp | 𝑥 ≤ 2.0.17.2298 | ADP |
References