CVE-2023-29062
Estado: ModificadaBaja (3.8)—
The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
- Puntuación base: 3.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 20
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-287
- CWE-287
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-29062",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@bd.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 3.8,
"attackVector": "ADJACENT_NETWORK",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 2.1
}
]
},
"affected": [
{
"source": "cybersecurity@bd.com",
"affectedData": [
{
"vendor": "Becton, Dickinson and Company (BD)",
"product": "FACSChorus",
"versions": [
{
"status": "affected",
"version": "5.0",
"versionType": "custom",
"lessThanOrEqual": "5.1"
},
{
"status": "affected",
"version": "3.0",
"versionType": "custom",
"lessThanOrEqual": "3.1"
}
],
"platforms": [
"Windows",
"64 bit"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-11-28T21:15:07.440",
"references": [
{
"url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@bd.com"
},
{
"url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@bd.com",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-287"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is possible through the use of LLMNR, MBT-NS, or MDNS and will result in NTLMv2 hashes being sent to a malicious entity position on the local network. These hashes can subsequently be attacked through brute force and cracked if a weak password is used. This attack would only apply to domain joined systems."
},
{
"lang": "es",
"value": "El sistema operativo que aloja la aplicación FACSChorus está configurado para permitir la transmisión de credenciales de usuario con hash tras la acción del usuario sin validar adecuadamente la identidad del recurso solicitado. Esto es posible mediante el uso de LLMNR, MBT-NS o MDNS y dará como resultado el envío de hashes NTLMv2 a una posición de entidad maliciosa en la red local. Posteriormente, estos hashes pueden atacarse mediante fuerza bruta y descifrarse si se utiliza una contraseña débil. Este ataque sólo se aplicaría a sistemas unidos a un dominio."
}
],
"lastModified": "2026-06-17T05:49:17.487",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D5E0D4F-559B-414E-A627-0BA0937BD7F1"
},
{
"criteria": "cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57F63FB2-2AE2-4B5F-8B49-4A0A4549CF3E"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "54279DE4-A2A4-4AA6-A05F-931094446F16"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2785D17E-800C-4772-A131-5737E9446C01"
},
{
"criteria": "cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "30FD1DE4-982F-4D14-BB8A-478F8430BC63"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7E9BA28D-9C14-435A-9786-222BE58A9258"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cybersecurity@bd.com"
}