HIGH
Arbitrary file write via WebDAV path traversal in Titan MFT and Titan SFTP servers
Published Oct 16, 2023
7.2
HIGHCVSS 3.1
EPSS 1.00%
Description
Insufficient path validation when writing a file via WebDAV in South River Technologies' Titan MFT and Titan SFTP servers on Linux allows an authenticated attacker to write a file to any location on the filesystem via path traversal
Affected products
-
- Version 0StatusaffectedConstraints<=2.0.17.2298
- Version
-
- Version 0StatusaffectedConstraints<=2.0.17.2298
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| South River Technologies | Titan MFT | unaffected |
| ||||||
| South River Technologies | Titan SFTP | unaffected |
|
- < 2.0.18
-
- Version 0StatusaffectedConstraints<2.0.18
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Southrivertech | Titan Mfp Server | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690 Vendor Advisory
- https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/ ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690 | Vendor Advisory | |
| https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/ | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Oct 16, 2023
Updated Sep 16, 2024
Reserved Oct 10, 2023
Link CVE-2023-45686
CISA Vulnrichment
Updated Sep 16, 2024