CVE-2024-22318 MEDIUM

CVE-2024-22318: IBM i Access Client Solutions information disclosure

Vendor Ibm
Product i Access Client Solutions
Weakness CWE-327 · Broken crypto
Published February 9, 2024
Last update September 20, 2024

CVSS base score

5.1/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate using the current user's session. The hostile server could capture the NTLM hash information to obtain the user's credentials. IBM X-Force ID: 279091.

Key dates

02Disclosure timeline

February 9, 2024 CVE published
September 20, 2024 Record updated