Unrated severityNVD Advisory· Published Dec 31, 2020· Updated Sep 17, 2024
CHANGING Inc. NHIServiSignAdapter Windows Versions - Information Leakage -2
CVE-2020-25846
Description
The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
Affected products
1- Range: 1.0.20.0218
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.twcert.org.tw/tw/cp-132-4274-7bd65-1.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.