PT-2025-9317 · Unknown · Advanced Port Scanner+1
Alejandro Baño Andrés
+3
·
Publicado
2025-03-03
·
Atualizado
2026-01-07
·
CVE-2025-1868
CVSS v3.1
6.8
Média
| Vetor | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Advanced IP Scanner (affected versions not specified)
Advanced Port Scanner (affected versions not specified)
Description
The issue involves the unauthorized exposure of confidential information when the applications initiate a network scan, sending the NTLM hash of the user performing the scan. This can be exploited by intercepting network traffic to a legitimate server or by setting up a fake server, affecting both local and remote scenarios, and is relevant for both HTTP/HTTPS and SMB protocols.
Recommendations
For Advanced IP Scanner, consider restricting the use of the network scan feature until a fix is available.
For Advanced Port Scanner, avoid using the network scan functionality until the issue is resolved.
As a temporary workaround, consider disabling the network scan feature in both applications to minimize the risk of exploitation.
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advanced Ip Scanner
Advanced Port Scanner