PT-2026-68903 · Teamdavid · Teamdavid
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
TeamDavid versions prior to Rollout 525
Description
The move archive functionality (
!ArcEntryMove) in the Webbox component processes the pathname parameter without proper validation. This allows an attacker to provide arbitrary paths, including Universal Naming Convention (UNC) paths, which trigger outbound connection attempts to external SMB servers. This behavior can lead to the exposure of NTLM authentication information, such as NTLM hashes, enabling SMB relay or credential theft attacks if outbound connections to port 445 are permitted. This issue can be exploited without authentication.Recommendations
Update to a version later than Rollout 524.
Restrict outbound connections to port 445 (SMB) to minimize the risk of credential theft.
Fix
RCE
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teamdavid