VYPR

Nhiservisignadapter

by Panorama Project

CVEs (2)

  • CVE-2020-25846HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.

  • CVE-2020-25845HigDec 31, 2020
    risk 0.49cvss 7.5epss 0.01

    Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.