IBM i Access Client Solutions information disclosure
33Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 5.1epss 0.6%
de la publicación al arma17 días
Publicada en NVD9 feb
1ª PoC+17d
probabilidad de explotación
0.6%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Productos afectados
IBM · i Access Client SolutionsPoCs públicas encontradas — 2
exploitdbwww.exploit-db.com/exploits/51817no verificadocve_referencepacketstormsecurity.com/files/177069/IBM-i-Access-Client-Solutions-Remote-Credential-Theft.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.