System operacyjny hostujący aplikację FACSChorus jest skonfigurowany tak, aby transmitować zahashowane dane uwierzytelniające użytkownika na żądanie bez odpowiedniego walidowania tożsamości żądanego zasobu. Jest to możliwe dzięki wykorzystaniu LLMNR, MBT-NS lub MDNS i powoduje wysłanie hashów NTLMv2 do złośliwego podmiotu umiejscowionego w sieci lokalnej. Te hashe mogą następnie być atakowane metodą brute force i złamane, jeśli zastosowano słabe hasło. Atak ten dotyczy wyłącznie systemów dołączonych do domeny.
▸ Pokaż oryginał (EN)
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems.
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:NBd Facschorus
APPBd3.03.15.05.1HP Z2 Tower G5
HWHpwszystkie wersjeHP Z2 Tower G9
HWHpwszystkie wersje
Powiązane podatności
The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If...
There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstatio...
The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcode...
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user....
Stacja robocza FACSChorus nie zapobiega fizycznym dostępem do slotów PCI express (PCIe), co pozwala atakującem...