Vulnerability of unauthorized exposure of confidential information affecting Advanced IP Scanner and Advanced Port Scanner. It occurs when these applications initiate a network scan, inadvertently sending the NTLM hash of the user performing the scan. This vulnerability can be exploited by intercepting network traffic to a legitimate server or by setting up a fake server, in both local and remote scenarios. This exposure is relevant for both HTTP/HTTPS and SMB protocols.
CVE ID: CVE-2025-1868
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.9
CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vendor: Famatech Corp, Famatech Corp
Product: Advanced IP Scanner, Advanced Port Scanner
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 1.86% (scored less or equal to compared to others)
EPSS Date: 2025-04-01 (when was this score calculated)