Thorntech's vulnerability profile centers on its SFTP Gateway product line, a narrowly scoped file-transfer appliance deployed in secure data exchange environments. The durable signal is concentrated in firmware and application components handling serialized data and cryptographic validation, with recurring weaknesses in untrusted deserialization and improper integrity-check validation that reflect the parsing demands of protocol-compliant secure file handling. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thorntech over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2023-47174CRITICAL Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-10000 | Oct 31, 2023 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thorntech.
Media articles that mention a CVE ID that affects a product developed by Thorntech — matched by CVE ID, not by vendor name.