Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 13 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Southrivertech
Southrivertech titan Sftp Server
Weaknesses CWE-200
CPEs cpe:2.3:a:southrivertech:titan_sftp_server:*:*:*:*:*:linux:*:*
Vendors & Products Southrivertech
Southrivertech titan Sftp Server
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 16:00:00 +0000

Type Values Removed Values Added
Description Titan SFTP and Titan MFT Server 2.0.25.2426 and earlier have a vulnerability a vulnerability where sensitive information, including passwords, is exposed in clear text within the JSON response when configuring SMTP settings via the Web UI.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-09-13T18:39:28.746Z

Reserved: 2024-08-21T00:00:00

Link: CVE-2024-44685

cve-icon Vulnrichment

Updated: 2024-09-13T18:35:18.253Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-09-13T16:15:04.297

Modified: 2024-09-13T19:35:14.350

Link: CVE-2024-44685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.