CVE-2024-44685

MEDIUM

Titan SFTP & Titan MFT Server <2.0.25.2426 - Info Disclosure

Title source: llm
STIX 2.1

Description

Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.

Scores

CVSS v3 5.0
EPSS 0.0014
EPSS Percentile 33.1%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Published Sep 13, 2024
Tracked Since Feb 18, 2026