ACEweb Online Portal 3.5.065 allows unauthenticated SMB hash capture via UNC. By specifying the UNC file path of an external SMB share when uploading a file, an attacker can induce the victim server to disclose the username and password hash of the user executing the ACEweb Online software.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.aceware.com/forum/viewtopic.php?f=7&t=481 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published: 2022-05-27T18:29:47.000Z
Updated: 2026-07-09T00:17:16.982Z
Reserved: 2022-02-07T00:00:00.000Z
Link: CVE-2022-24581
No data.
Status : Modified
Published: 2022-06-02T14:15:37.103
Modified: 2026-07-09T01:17:17.743
Link: CVE-2022-24581
No data.
ReportizFlow