CVE-2023-29446
4.7
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 1.0 / Impact: 3.6
Source: NVD
Description
An improper input validation vulnerability has been discovered that could allow an adversary to inject a UNC path via a malicious project file. This allows an adversary to capture NLTMv2 hashes and potentially crack them offline.
Affected (3)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.0.2107.0 to 6.14.263.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 6.8 to 6.14.263.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| From 8.0 to 8.5 |
Related CWEs
CWE-20
Improper Input Validation
The product receives input or data, but it does
not validate or incorrectly validates that the input has the
properties that are required to process the data safely and
correctly.
CWE-40
Path Traversal: '\\UNC\share\name\' (Windows UNC Share)
The product accepts input that identifies a Windows UNC share ('\\UNC\share\name') that potentially redirects access to an unintended location or arbitrary file.
References (6)
Source: ot-cert@dragos.com
Third Party AdvisoryUS Government Resource
Source: ot-cert@dragos.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.