CVE-2023-45687 Vulnerability Details

  /     /     /  

CVE-2023-45687 Metadata Quick Info

CVE Published: 16/10/2023 | CVE Updated: 16/09/2024 | CVE Year: 2023
Source: rapid7 | Vendor: South River Technologies | Product: Titan MFT
Status : PUBLISHED

CVE-2023-45687 Description

A session fixation vulnerability in South River Technologies\' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server\'s authentication if they can trick an administrator into authorizating a session id of their choosing

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-384
CWE Name: CWE-384 Session Fixation
Source: South River Technologies

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).