Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*", "matchCriteriaId": "4D5E0D4F-559B-414E-A627-0BA0937BD7F1", "vulnerable": true}, {"criteria": "cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*", "matchCriteriaId": "57F63FB2-2AE2-4B5F-8B49-4A0A4549CF3E", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*", "matchCriteriaId": "54279DE4-A2A4-4AA6-A05F-931094446F16", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*", "matchCriteriaId": "2785D17E-800C-4772-A131-5737E9446C01", "vulnerable": true}, {"criteria": "cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*", "matchCriteriaId": "30FD1DE4-982F-4D14-BB8A-478F8430BC63", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*", "matchCriteriaId": "7E9BA28D-9C14-435A-9786-222BE58A9258", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems."}, {"lang": "es", "value": "El sistema operativo que aloja la aplicaci\u00f3n FACSChorus est\u00e1 configurado para permitir la transmisi\u00f3n de credenciales de usuario con hash tras la acci\u00f3n del usuario sin validar adecuadamente la identidad del recurso solicitado. Esto es posible mediante el uso de LLMNR, MBT-NS o MDNS y dar\u00e1 como resultado el env\u00edo de hashes NTLMv2 a una posici\u00f3n de entidad maliciosa en la red local. Posteriormente, estos hashes pueden atacarse mediante fuerza bruta y descifrarse si se utiliza una contrase\u00f1a d\u00e9bil. Este ataque s\u00f3lo se aplicar\u00eda a sistemas unidos a un dominio."}], "id": "CVE-2023-29062", "lastModified": "2024-11-21T07:56:29.017", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 3.8, "baseSeverity": "LOW", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 2.1, "impactScore": 1.4, "source": "cybersecurity@bd.com", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "ADJACENT_NETWORK", "availabilityImpact": "NONE", "baseScore": 3.8, "baseSeverity": "LOW", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 2.1, "impactScore": 1.4, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2023-11-28T21:15:07.440", "references": [{"source": "cybersecurity@bd.com", "tags": ["Vendor Advisory"], "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software"}], "sourceIdentifier": "cybersecurity@bd.com", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-287"}], "source": "cybersecurity@bd.com", "type": "Secondary"}, {"description": [{"lang": "en", "value": "CWE-287"}], "source": "nvd@nist.gov", "type": "Primary"}]}