PT-2018-9732 · Digital Guardian · Digital Guardian Management Console

Published

2018-04-20

·

Updated

2018-05-22

·

CVE-2018-10174

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Digital Guardian Management Console version 7.1.2.0015
Description: The issue allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.
Recommendations: For Digital Guardian Management Console version 7.1.2.0015, consider restricting access to the management console to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability to read arbitrary files and send TCP traffic to intranet hosts. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-10174

Affected Products

Digital Guardian Management Console