First published: Tue Oct 31 2023(Updated: )
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Thorntech Sftp Gateway Firmware | >=3.4.0<3.4.4 | |
Thorntech Sftp Gateway |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-47174 is a vulnerability in Thorn SFTP gateway 3.4.x before 3.4.4 that allows remote code execution through Java deserialization of untrusted data.
The severity of CVE-2023-47174 is critical with a CVSS score of 9.8.
CVE-2023-47174 affects Thorn SFTP gateway versions 3.4.x before 3.4.4 and can lead to remote code execution.
To fix CVE-2023-47174, users should update Thorn SFTP gateway to version 3.4.4 or higher.
More information about CVE-2023-47174 can be found at the following link: [https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/](https://help.thorntech.com/docs/sftp-gateway-gcp-3.0/gcp-java-deserialization-rce/)