Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2j57-prq3-h7v2

Опубликовано: 20 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).

EPSS

Процентиль: 71%
0.00698
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.6
nvd
почти 2 года назад

Arbitrary Authentication Relay and Session Hijack vulnerabilities in the deprecated VMware Enhanced Authentication Plug-in (EAP) could allow a malicious actor that could trick a target domain user with EAP installed in their web browser into requesting and relaying service tickets for arbitrary Active Directory Service Principal Names (SPNs).

CVSS3: 9.6
fstec
почти 2 года назад

Уязвимость модуля расширенной аутентификации VMware Enhanced Authentication Plug-in (EAP), связанная с недостатками процедуры аутентификации, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 71%
0.00698
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-287