PT-2020-20584 · Aquaforest · Aquaforest Tiff Server

Published

2020-03-18

·

Updated

2020-03-20

·

CVE-2020-9324

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Aquaforest TIFF Server version 4.0
Description The issue allows for unauthenticated SMB hash capture via UNC.
Recommendations For Aquaforest TIFF Server version 4.0, consider restricting access to the SMB service until a patch is available. As a temporary workaround, disabling the UNC functionality may help minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-9324

Affected Products

Aquaforest Tiff Server