Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The vulnerability has been fixed by the Sage team in version 2025.35.000.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6243 | SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker. |
Fri, 07 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Mar 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SMB forced authentication vulnerability in versions prior to 2025.35.000 of Sage 200 Spain. This vulnerability allows an authenticated attacker with administrator privileges to obtain NTLMv2-SSP Hash by changing any of the paths to a UNC path pointing to a server controlled by the attacker. | |
| Title | SMB forced authentication vulnerability in Sage 200 Spain | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2025-03-07T13:31:40.805Z
Reserved: 2025-03-03T13:11:18.262Z
Link: CVE-2025-1887
Updated: 2025-03-07T13:30:14.425Z
Status : Deferred
Published: 2025-03-07T11:15:16.040
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-1887
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:24Z
EUVD