CVE-2023-40235

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 10, 2023
Updated: Aug 21, 2023

Summary

CVE-2023-40235 is an NTLM Hash Disclosure vulnerability affecting ArchiMate Archi versions prior to 5.1.0. During the processing of an ArchiMate project file's XMLNS value, the parser attempts to access a resource provided if the URL does not match the expected ArchiMate URL. If the resource is a UNC path pointing to an unsecured share server, the host will attempt to authenticate using the current user's session, potentially disclosing NTLM hashes. This vulnerability arises due to the Archi software's unsafe configuration of the Eclipse Modeling Framework.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share