Lucene search

K
cveMitreCVE-2023-47174
HistoryOct 31, 2023 - 4:15 a.m.

CVE-2023-47174

2023-10-3104:15:11
CWE-502
mitre
web.nvd.nist.gov
45
thorn sftp gateway
cve-2023-47174
java deserialization
remote code execution
nvd

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.024

Percentile

90.1%

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

Affected configurations

Nvd
Node
thorntechsftp_gateway_firmwareRange3.4.03.4.4
AND
thorntechsftp_gatewayMatch-
VendorProductVersionCPE
thorntechsftp_gateway_firmware*cpe:2.3:o:thorntech:sftp_gateway_firmware:*:*:*:*:*:*:*:*
thorntechsftp_gateway-cpe:2.3:h:thorntech:sftp_gateway:-:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.7

Confidence

High

EPSS

0.024

Percentile

90.1%