vulnerability

Titan MFT: CVE-2023-45685: Arbitrary file overwrite

Severity
8
CVSS
(AV:N/AC:M/Au:M/C:C/I:C/A:C)
Published
Oct 16, 2023
Added
Oct 16, 2023
Modified
Oct 26, 2023

Description


Titan MFT and Titan SFTP have a feature where .zip files can be automatically extracted when they are uploaded over any supported protocol. Files within the .zip archive are not validated for path traversal characters; as a result, an authenticated attacker can upload a .zip file containing a filename such as `../../file`, which will be extracted outside the user's home directory. If an attacker can write a file to anywhere on the file system, they can leverage that to gain remote access in several different ways.

Solution

titan-mft-october-updates
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.