Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-25166

Опубликовано: 14 апр. 2022
Источник: nvd
CVSS3: 5
CVSS2: 4.3
EPSS Низкий

Описание

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

Комментарий

At the time of analysis the advisory information and CVE List data did not consistently identify which data was applicable to CVE-2022-25166 and CVE-2022-25165. We have associated metadata based on what was published to the official CVE List.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:amazon:aws_client_vpn:2.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.0114
Низкий

5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 5
github
почти 4 года назад

An issue was discovered in Amazon AWS VPN Client 2.0.0. It is possible to include a UNC path in the OpenVPN configuration file when referencing file paths for parameters (such as auth-user-pass). When this file is imported and the client attempts to validate the file path, it performs an open operation on the path and leaks the user's Net-NTLMv2 hash to an external server. This could be exploited by having a user open a crafted malicious ovpn configuration file.

CVSS3: 7.3
fstec
почти 4 года назад

Уязвимость службы AWS VPN Client, связанная с ошибками синхронизации при использовании общего ресурса, позволяющая нарушителю повысить свои привилегии или вызвать отказ в обслуживании

EPSS

Процентиль: 78%
0.0114
Низкий

5 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-200