Exploitation Summary
EIP tracks 1 public exploit for CVE-2022-34298. PoCs published by watchtowrlabs.
AI-analyzed exploit summary This PoC exploits an authentication impersonation vulnerability in OpenAM by injecting a crafted payload into the password field, allowing an attacker to log in as another user. The script demonstrates the vulnerability by performing a valid login and then impersonating a victim user.
Description
The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."
Exploits (1)
This PoC exploits an authentication impersonation vulnerability in OpenAM by injecting a crafted payload into the password field, allowing an attacker to log in as another user. The script demonstrates the vulnerability by performing a valid login and then impersonating a victim user.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N