← volver
CVE-2024-22318mediumCWE-327

IBM i Access Client Solutions information disclosure

33Vexday Risk Score

Sin señal de explotación. Ella tiene prueba de concepto pública.

ssvc Attendcvss 5.1epss 0.6%
de la publicación al arma17 días
Publicada en NVD9 feb
1ª PoC+17d
probabilidad de explotación
0.6%top 56% de las CVE
explotación observada
noninguna fuente lo reporta
2 exploit(s) público(s)
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.