CVE-2023-47174
Thorn SFTP Gateway vulnerability analysis and mitigation

Overview

A critical vulnerability (CVE-2023-47174) was discovered in Thorn SFTP Gateway versions 3.4.0 through 3.4.3. The vulnerability stems from the use of Pivotal Spring Framework for Java deserialization of untrusted data, which is related to CVE-2016-1000027. This vulnerability affects the web admin portal of SFTP Gateway, a solution that facilitates secure file transfers between SFTP clients and cloud storage providers such as Amazon S3, Azure Blob Storage, and Google Cloud Storage (Security Online).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 9.8 (CRITICAL) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue is classified under CWE-502 (Deserialization of Untrusted Data) and specifically involves the processing of untrusted Java deserialized data through the Pivotal Spring Framework (NVD).

Impact

The vulnerability enables remote code execution (RCE) capabilities, allowing an attacker to execute arbitrary code on the SFTP Gateway server through the web admin portal. This poses a significant security risk as it could lead to complete system compromise (Security Online).

Mitigation and workarounds

Organizations are advised to implement several mitigation measures: 1) Upgrade to SFTP Gateway version 3.4.4 which contains the patch, 2) Restrict port 443 access to sysadmin IP addresses only, and 3) Review and remove any network ingress rules on port 443 that allow the range 0.0.0.0/0. For those unable to upgrade immediately, it's crucial to verify that the web admin portal is locked down to specific IP addresses (Thorn Advisory).

Additional resources


SourceThis report was generated using AI

Related Thorn SFTP Gateway vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-47174CRITICAL9.8
  • Thorn SFTP GatewayThorn SFTP Gateway
  • cpe:2.3:o:thorntech:sftp_gateway_firmware
NoYesOct 31, 2023
CVE-2023-48795MEDIUM5.9
  • PythonPython
  • nebula
NoYesDec 18, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management