SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker. | |
| Title | SMB forced authentication vulnerability in Sage 200 Spain | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published: 2025-03-07T10:56:52.391Z
Updated: 2025-03-07T13:31:40.805Z
Reserved: 2025-03-03T13:11:18.262Z
Link: CVE-2025-1887
Updated: 2025-03-07T13:30:14.425Z
Status : Received
Published: 2025-03-07T11:15:16.040
Modified: 2025-03-07T11:15:16.040
Link: CVE-2025-1887
No data.