CVE-2024-44685
MEDIUMTitan SFTP & Titan MFT Server <2.0.25.2426 - Info Disclosure
Title source: llmDescription
Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.
References (2)
Core 2
Core References
Scores
CVSS v3
5.0
EPSS
0.0014
EPSS Percentile
33.1%
Attack Vector
PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Published
Sep 13, 2024
Tracked Since
Feb 18, 2026