Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)
Advisories
Source ID Title
EUVD EUVD EUVD-2023-50798 Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)
Fixes

Solution

Upgrade ASMS suite to A32.20 (b570 or above),  A32.50 (b390 or above) https://portal.algosec.com/en/downloads/hotfix_releases https://portal.algosec.com/en/downloads/hotfix_releases


Workaround

No workaround given by the vendor.

History

Wed, 12 Nov 2025 09:00:00 +0000

Type Values Removed Values Added
Description Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above) Net-NTLM leak via HTML injection in FireFlow VisualFlow workflow editor allows an attacker to obtain victim’s domain credentials and Net-NTLM hash which can lead to relay domain attacks. Fixed in A32.20 (b570 or above), A32.50 (b390 or above)

cve-icon MITRE

Status: PUBLISHED

Assigner: AlgoSec

Published:

Updated: 2025-11-12T08:38:33.676Z

Reserved: 2023-10-23T10:00:57.893Z

Link: CVE-2023-46595

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2023-11-02T08:15:08.040

Modified: 2025-11-12T09:15:40.030

Link: CVE-2023-46595

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.