Sage 200 Spain
cpe:2.3:a:sage:sage_200_spain:*:*:*:*:*:*:*
- < 2025.35.000
A vulnerability exists in Sage 200 Spain versions prior to 2025.35.000, allowing authenticated attackers with administrator privileges to exploit SMB forced authentication. By altering any file path to a UNC path that points to a server controlled by the attacker, the NTLMv2-SSP hash can be obtained.
Exploitation of this vulnerability allows for the retrieval of NTLMv2-SSP hashes, which could be used in pass-the-hash attacks or to gain unauthorized access to resources.
Users can upgrade to Sage 200 Spain version 2025.35.000 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.