CVE-2020-25845
Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user’s credential.
Summary:
Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user’s credential.
Reference Links(if available):
CVSS Score (if available)
v2: 4.3 / MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
v3: 7.4 / HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N