Vulnerability Description
S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a malicious server via the S3 protocol.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| S3Browser | S3 Browser | < 8.1.5 |
Related Weaknesses (CWE)
References
- https://s3browser.com/news.aspxRelease NotesVendor Advisory
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-34/Third Party Advisory
- https://s3browser.com/news.aspxRelease NotesVendor Advisory
- https://www.ptsecurity.com/ww-en/analytics/threatscape/pt-2018-34/Third Party Advisory
FAQ
What is CVE-2018-20298?
CVE-2018-20298 is a vulnerability with a CVSS score of 6.5 (MEDIUM). S3 Browser before 8.1.5 contains an XML external entity (XXE) vulnerability, allowing remote attackers to read arbitrary files and obtain NTLMv2 hash values by tricking a user into connecting to a mal...
How severe is CVE-2018-20298?
CVE-2018-20298 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20298?
Check the references section above for vendor advisories and patch information. Affected products include: S3Browser S3 Browser.