CVE-2023-45687
Authentication bypass via session fixation in Titan MFT and Titan SFTP servers
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they can trick an administrator into authorizating a session id of their choosing
Una vulnerabilidad de fijación de sesión en los servidores Titan MFT y Titan SFTP de South River Technologies en Linux y Windows permite a un atacante eludir la autenticación del servidor si puede engañar a un administrador para que autorice una identificación de sesión de su elección.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-10-10 CVE Reserved
- 2023-10-16 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- 2024-11-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-384: Session Fixation
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed | 2024-09-16 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Southrivertech Search vendor "Southrivertech" | Titan Mft Server Search vendor "Southrivertech" for product "Titan Mft Server" | < 2.0.18 Search vendor "Southrivertech" for product "Titan Mft Server" and version " < 2.0.18" | linux |
Affected
| ||||||
Southrivertech Search vendor "Southrivertech" | Titan Mft Server Search vendor "Southrivertech" for product "Titan Mft Server" | < 2.0.18 Search vendor "Southrivertech" for product "Titan Mft Server" and version " < 2.0.18" | windows |
Affected
| ||||||
Southrivertech Search vendor "Southrivertech" | Titan Sftp Server Search vendor "Southrivertech" for product "Titan Sftp Server" | < 2.0.18 Search vendor "Southrivertech" for product "Titan Sftp Server" and version " < 2.0.18" | linux |
Affected
| ||||||
Southrivertech Search vendor "Southrivertech" | Titan Sftp Server Search vendor "Southrivertech" for product "Titan Sftp Server" | < 2.0.18 Search vendor "Southrivertech" for product "Titan Sftp Server" and version " < 2.0.18" | windows |
Affected
|