動作
專案資訊 #1073
進行中專案資訊 #1064: 2025-PenTest
SMB NULL Session Authentication allowed on Domain Controllers
開始日期:
2025-08-01
完成日期:
2025-12-31 (逾期 25 天)
完成百分比:
100%
預估工時:
概述
"4.7.3
CWE-16
CWE-284
" "SMB NULL Session Authentication allowed on Domain Controllers
The SMB service on domain controllers allows users to authenticate using a NULL session, meaning that no user credentials need to be supplied to the server.
" "An attacker may be able to read, delete or modify important data, and depending on the configuration, it could be possible to list information about the domain such as users and groups.
" "Disallow the possibility to authenticate to the SMB server using NULL sessions, if this is not possible, do not store sensitive data in public shares.
" "Status: Open
CVSS-Score: 6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Fix Difficulty: Quick Win
"
檔案
動作
