Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr32-5vpv-693c

Опубликовано: 07 мар. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.

SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.

EPSS

Процентиль: 32%
0.00122
Низкий

7.1 High

CVSS4

Дефекты

CWE-294

Связанные уязвимости

nvd
11 месяцев назад

SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.

EPSS

Процентиль: 32%
0.00122
Низкий

7.1 High

CVSS4

Дефекты

CWE-294