CVE-2023-47174: Thorntech Sftp Gateway Firmware

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.

Affected products

  • Thorntech Sftp Gateway Firmware: from 3.4.0, before 3.4.4 (fixed in 3.4.4)

Published 2023-10-31. Last modified 2026-06-17.