PT-2018-12613 · Thomson Reuters · Thomson Reuters Ultratax Cs

User

·

Publicado

2018-07-26

·

Atualizado

2024-02-14

·

CVE-2018-14607

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Thomson Reuters UltraTax CS version 2017
Description The software transfers customer records and bank account numbers in cleartext over SMBv2, allowing attackers to obtain sensitive information by sniffing the network or conduct man-in-the-middle (MITM) attacks. The customer record transferred in cleartext contains sensitive information such as Client ID, Full Name, Social Security Number, Bank Name, Bank Account Number, and other personal details.
Recommendations For Thomson Reuters UltraTax CS version 2017, consider implementing encryption for data transferred over the network to prevent eavesdropping and MITM attacks. As a temporary workaround, restrict access to the network to minimize the risk of exploitation. Avoid using SMBv2 for sensitive data transfer until a secure alternative is implemented.

Exploit

Correção

Missing Encryption of Sensitive Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-14607

Produtos afetados

Thomson Reuters Ultratax Cs