CVE-2023-45689

MEDIUM

Titan MFT and SFTP Server < 2.0.18 - Authenticated Path Traversal

Title source: llm
STIX 2.1

Description

Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal

Scores

CVSS v3 6.5
EPSS 0.0082
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
southrivertech/titan_mft_server < 2.0.18 (2 CPE variants)
southrivertech/titan_sftp_server < 2.0.18 (2 CPE variants)
Published Oct 16, 2023
Tracked Since Feb 18, 2026