CHANGING Inc. NHIServiSignAdapter Windows Versions - Information Leakage -2
CVE-2020-25846
7.5HIGH
What is CVE-2020-25846?
The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
Affected Version(s)
NHIServiSignAdapter Windows 1.0.20.0218
