動作
專案資訊 #1073
已結束專案資訊 #1064: 2025-PenTest
SMB NULL Session Authentication allowed on Domain Controllers
狀態:
Closed-關閉
優先權:
Normal
被分派者:
周益利
分類:
-
開始日期:
2025-08-01
完成日期:
2025-12-31
完成百分比:
100%
預估工時:
概述
"4.7.3
CWE-16
CWE-284
" "SMB NULL Session Authentication allowed on Domain Controllers
The SMB service on domain controllers allows users to authenticate using a NULL session, meaning that no user credentials need to be supplied to the server.
" "An attacker may be able to read, delete or modify important data, and depending on the configuration, it could be possible to list information about the domain such as users and groups.
" "Disallow the possibility to authenticate to the SMB server using NULL sessions, if this is not possible, do not store sensitive data in public shares.
" "Status: Open
CVSS-Score: 6.5
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Fix Difficulty: Quick Win
"
檔案
動作
