CVE-2018-10174
Last modified
CVE-2018-10174 is a vulnerability of currently unknown severity. Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Digital Guardian Management Console 7.1.2.0015 has an SSRF issue that allows remote attackers to read arbitrary files via file:// URLs, send TCP traffic to intranet hosts, or obtain an NTLM hash. This can occur even if the logged-in user has a read-only role.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Digitalguardian | Management Console | 7.1.2.0015 |
References
- http://packetstormsecurity.com/files/147260/Digital-Guardian-Management-Console-7.1.2.0015-Server-Side-Request-Forgery.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/147260/Digital-Guardian-Management-Console-7.1.2.0015-Server-Side-Request-Forgery.htmlThird Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-10174?
How severe is CVE-2018-10174?
How do I fix CVE-2018-10174?
Are you affected by CVE-2018-10174?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
