Southrivertech develops a focused portfolio of file-transfer and managed-file-transfer (MFT) server products, including Titan FTP Server, Titan SFTP Server, Titan MFT Server, and WebDrive, which are deployed in enterprise environments where secure data exchange is critical. The vendor's vulnerability exposure, while modest in volume, recurs through weakness classes characteristic of file-handling and protocol-parsing complexity: path-traversal flaws, code-injection conditions, improper parameter handling, and privilege-management gaps that reflect the server's role in authenticating and mediating access to shared resources. A notable share of disclosures acquire public exploit code, consistent with the appeal of file-transfer appliances as targets for lateral movement and data exfiltration. Defenders should monitor this vendor's advisories for path-traversal and authentication-bypass patterns, particularly where instances are internet-exposed or handle sensitive data; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Southrivertech over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6082MEDIUM Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO command. | Feb 6, 2009 | 5.0 | 54 | NO | YES |
CVE-2023-22629HIGH An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the newPath parameter. An authenticated attacker can upload any | Feb 14, 2023 | 8.8 | 52 | NO | YES |
CVE-2014-1843MEDIUM Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to obtain the property information of an arbitrary home f | Apr 29, 2014 | 5.0 | 37 | NO | YES |
CVE-2019-10009MEDIUM A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated user attempts to preview an uploaded file (through PreviewHandl | Jun 3, 2019 | 6.5 | 36 | NO | YES |
CVE-2014-1842MEDIUM Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to list all usernames via a Go action with a .. (dot dot) | Apr 29, 2014 | 5.0 | 33 | NO | YES |
CVE-2014-1841MEDIUM Directory traversal vulnerability in the web interface in Titan FTP Server before 10.40 build 1829 allows remote attackers to copy an arbitrary user's home folder via a Move action | Apr 29, 2014 | 5.0 | 33 | NO | YES |
CVE-2022-34005CRITICAL An issue was discovered in TitanFTP (aka Titan FTP) NextGen before 1.2.1050. There is Remote Code Execution due to a hardcoded password for the sa account on the Microsoft SQL Expr | Jun 19, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-45685CRITICAL Insufficient path validation when extracting a zip archive in South River Technologies' Titan MFT and Titan SFTP servers on Windows and Linux allows an authenticated attacker to wr | Oct 16, 2023 | 9.1 | 28 | NO | NO |
CVE-2023-45687HIGH A session fixation vulnerability in South River Technologies' Titan MFT and Titan SFTP servers on Linux and Windows allows an attacker to bypass the server's authentication if they | Oct 16, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-27745HIGH An issue in South River Technologies TitanFTP Before v2.0.1.2102 allows attackers with low-level privileges to perform Administrative actions by sending requests to the user server | Jun 2, 2023 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Southrivertech.
Media articles that mention a CVE ID that affects a product developed by Southrivertech — matched by CVE ID, not by vendor name.