Beveiligingsadvies

CVE-2025-1887

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-03-07 10:56:52
Laatst bijgewerkt 2025-03-07 13:31:40
Toegewezen door INCIBE
CVSS-score 7.1
Status PUBLISHED

Beschrijving

SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker.