CVE-2022-34005 describes a Remote Code Execution vulnerability in TitanFTP NextGen versions prior to 1.2.1050, stemming from a hardcoded 'sa' account password in the default Microsoft SQL Express 2019 installation. This critical vulnerability, rated 9.8 CVSS, allows unauthenticated attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability. While a fix exists in new installations of version 1.2.1050, upgrades remain vulnerable. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.1050CPE matchmatch criteria | cpe:2.3:a:southrivertech:titan_ftp_server_nextgen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.