CVE-2023-29062
Last modified
CVE-2023-29062 is a low-severity vulnerability rated 3.8/10 on the CVSS scale. The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems.
Metrics
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bd | Facschorus | 5.0 |
| Bd | Facschorus | 5.1 |
| Bd | Facschorus | 3.0 |
| Bd | Facschorus | 3.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-29062?
How severe is CVE-2023-29062?
How do I fix CVE-2023-29062?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-29057A valid XCC user's local account permissions overrides their…8.8
- CVE-2023-29058A valid, authenticated XCC user with read-only permissions c…6.5
- CVE-2023-290593CX DesktopApp through 18.12.416 has embedded malicious code…7.8
- CVE-2023-2906Due to a failure in validating the length provided by an att…6.5
- CVE-2023-29060The FACSChorus workstation operating system does not restric…5.7
- CVE-2023-29061There is no BIOS password on the FACSChorus workstation. A t…5.2
- CVE-2023-29063The FACSChorus workstation does not prevent physical access …2.4
- CVE-2023-29064The FACSChorus software contains sensitive information store…4.3
- CVE-2023-29065The FACSChorus software database can be accessed directly wi…4.3
- CVE-2023-29066The FACSChorus software does not properly assign data access…3.5
- CVE-2023-29067A maliciously crafted X_B file when parsed through Autodesk®…7.8
- CVE-2023-29068A maliciously crafted file consumed through pskernel.dll fil…7.8
Are you affected by CVE-2023-29062?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
