{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-45689","assignerOrgId":"9974b330-7714-4307-a722-5648477acda7","state":"PUBLISHED","assignerShortName":"rapid7","dateReserved":"2023-10-10T19:07:28.771Z","datePublished":"2023-10-16T16:19:08.287Z","dateUpdated":"2024-09-16T18:05:30.684Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","platforms":["Linux","Windows"],"product":"Titan MFT","vendor":"South River Technologies","versions":[{"lessThanOrEqual":"2.0.17.2298","status":"affected","version":"0","versionType":"semver"}]},{"defaultStatus":"unaffected","platforms":["Linux","Windows"],"product":"Titan SFTP","vendor":"South River Technologies","versions":[{"lessThanOrEqual":"2.0.17.2298","status":"affected","version":"0","versionType":"semver"}]}],"datePublic":"2023-10-16T15:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal"}],"value":"Lack of sufficient path validation in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker with administrative privileges to read any file on the filesystem via path traversal"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-22","description":"CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"9974b330-7714-4307-a722-5648477acda7","shortName":"rapid7","dateUpdated":"2023-10-16T16:19:08.287Z"},"references":[{"url":"https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/"},{"url":"https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690"}],"source":{"discovery":"UNKNOWN"},"title":"Arbitrary file read via path traversal in Titan MFT and Titan SFTP servers","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T20:29:32.337Z"},"title":"CVE Program Container","references":[{"url":"https://www.rapid7.com/blog/post/2023/10/16/multiple-vulnerabilities-in-south-river-technologies-titan-mft-and-titan-sftp-fixed/","tags":["x_transferred"]},{"url":"https://helpdesk.southrivertech.com/portal/en/kb/articles/security-patch-for-issues-cve-2023-45685-through-cve-2023-45690","tags":["x_transferred"]}]},{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-16T18:04:05.617300Z","id":"CVE-2023-45689","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-16T18:05:30.684Z"}}]}}