Vulnerabilities > Aquaforest

DATE CVE VULNERABILITY TITLE RISK
2023-11-30 CVE-2023-6352 Path Traversal vulnerability in Aquaforest Tiff Server 4.2.210913
The default configuration of Aquaforest TIFF Server allows access to arbitrary file paths, subject to any restrictions imposed by Internet Information Services (IIS) or Microsoft Windows.
network
low complexity
aquaforest CWE-22
5.3
2020-03-18 CVE-2020-9325 Missing Authentication for Critical Function vulnerability in Aquaforest Tiff Server 4.0
Aquaforest TIFF Server 4.0 allows Unauthenticated Arbitrary File Download.
network
low complexity
aquaforest CWE-306
7.5
2020-03-18 CVE-2020-9324 Insufficiently Protected Credentials vulnerability in Aquaforest Tiff Server 4.0
Aquaforest TIFF Server 4.0 allows Unauthenticated SMB Hash Capture via UNC.
network
low complexity
aquaforest CWE-522
7.5
2020-03-18 CVE-2020-9323 Path Traversal vulnerability in Aquaforest Tiff Server 4.0
Aquaforest TIFF Server 4.0 allows Unauthenticated File and Directory Enumeration via tiffserver/tssp.aspx.
network
low complexity
aquaforest CWE-22
5.3