CVE-2023-40235
Last modified
CVE-2023-40235 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate project file, if the namespace does not match the expected ArchiMate URL, the parser will access the provided resource. EPSS estimates a 0.70% chance of exploitation in the next 30 days.
Description
An NTLM Hash Disclosure was discovered in ArchiMate Archi before 5.1.0. When parsing the XMLNS value of an ArchiMate project file, if the namespace does not match the expected ArchiMate URL, the parser will access the provided resource. If the provided resource is a UNC path pointing to a share server that does not accept a guest account, the host will try to authenticate on the share by using the current user's session. NOTE: this issue occurs because Archi uses an unsafe configuration of the Eclipse Modeling Framework.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Opengroup | Archi | < 5.1.0 |
References
- https://github.com/archimatetool/archi/issues/946Exploit, Issue Tracking, Vendor Advisory
- https://github.com/eclipse-emf/org.eclipse.emf/issues/8Exploit, Issue Tracking, Third Party Advisory
- https://github.com/archimatetool/archi/issues/946Exploit, Issue Tracking, Vendor Advisory
- https://github.com/eclipse-emf/org.eclipse.emf/issues/8Exploit, Issue Tracking, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-40235?
How severe is CVE-2023-40235?
How do I fix CVE-2023-40235?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-40221 The absence of filters when loading some sectio…8.8
- CVE-2023-40222In Ashlar-Vellum Cobalt versions prior to v12 SP2 Build (120…8.4
- CVE-2023-40223Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2023-40224MISP 2.4.174 allows XSS in app/View/Events/index.ctp.6.1
- CVE-2023-40225HAProxy through 2.0.32, 2.1.x and 2.2.x through 2.2.30, 2.3.…7.2
- CVE-2023-4023The All Users Messenger WordPress plugin through 1.24 does n…4.3
- CVE-2023-40236In Pexip VMR self-service portal before 3, the same SSH host…5.3
- CVE-2023-40238A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde I…5.5
- CVE-2023-40239Certain Lexmark devices (such as CS310) before 2023-08-25 al…7.5
- CVE-2023-4024The Radio Player plugin for WordPress is vulnerable to unaut…5.3
- CVE-2023-4025The Radio Player plugin for WordPress is vulnerable to unaut…5.3
- CVE-2023-40250Buffer Copy without Checking Size of Input ('Classic Buffer …8.8
Are you affected by CVE-2023-40235?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
