Aquaforest develops TIFF Server, a specialized document-processing application where the observed vulnerability exposure centers on access control and credential management weaknesses, including path traversal, insufficiently protected credentials, and missing authentication for critical functions. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aquaforest over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-9325HIGH Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download. | Mar 18, 2020 | 7.5 | 24 | NO | NO |
CVE-2020-9324HIGH Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC. | Mar 18, 2020 | 7.5 | 23 | NO | NO |
CVE-2020-9323MEDIUM Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx. | Mar 18, 2020 | 5.3 | 19 | NO | NO |
CVE-2023-6352MEDIUM The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft W | Nov 30, 2023 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aquaforest.
Media articles that mention a CVE ID that affects a product developed by Aquaforest — matched by CVE ID, not by vendor name.