← Back

CVE-2023-29062

nvd nist
Published: Nov 28, 2023Modified: Jun 17, 2026

JSON object

Loading...
3.8
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD

Description

The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems.

Affected (4)

Products: Bd: Facschorus
1 product
Facschorus
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bd
Version 5.0
Version 5.1
Running on/withPlatform Versions
Hp
Hp Z2 Tower G9
All versions
Configuration B
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bd
Version 3.0
Version 3.1
Running on/withPlatform Versions
Hp
Hp Z2 Tower G5
All versions

References (2)

Timeline

No history available yet.