CVE-2024-22318
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server.
Does this matter?
Lower severity and a low EPSS score (0.57%). Track it; it rarely justifies an emergency change on its own.
Description
IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.57% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327, CWE-384
- Affected
- ibm/i access client solutions
- Source
- psirt@us.ibm.com
References
- http://packetstormsecurity.com/files/177069/IBM-i-Access-Client-Solutions-Remote-Credential-Theft.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2024/Feb/7Mailing List, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/279091VDB Entry
- https://www.ibm.com/support/pages/node/7116091Vendor Advisory
- http://packetstormsecurity.com/files/177069/IBM-i-Access-Client-Solutions-Remote-Credential-Theft.htmlThird Party Advisory, VDB Entry
- http://seclists.org/fulldisclosure/2024/Feb/7Mailing List, Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/279091VDB Entry
- https://www.ibm.com/support/pages/node/7116091Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.