Sceawere

Vulnerability Detail

CVE-2026-73025UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Windows iSCSI Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
3h ago
Vendor
Microsoft
Product
Windows 10 Version 1607
Attack Type
CWE-1390: Weak Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Weak authentication in Windows iSCSI allows an unauthorized attacker to bypass a security feature over a network.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-09-08T18:20:32.490Z",
  "pubdate": "2026-09-08T18:20:32.490Z",
  "executiveSummary": "This vulnerability pertains to weak authentication mechanisms within the Windows iSCSI (Internet Small Computer System Interface) initiator/target implementation, which permits unauthorized network-based security feature bypasses.\nThe vulnerability is classified as an authentication bypass, allowing remote, unauthenticated attackers to circumvent established security controls within the iSCSI infrastructure.\nThe scope of impact includes unauthorized access to storage resources, potential data exfiltration, or modification, depending on the exposure of the iSCSI targets.\nWindows systems utilizing iSCSI for network-attached storage are susceptible to this flaw.\nRisk implications are high as the vulnerability facilitates unauthorized interaction with storage protocols without the requirement for valid credentials.\nExploitation is conducted over the network, meaning an attacker requires network line-of-sight to the target iSCSI port (typically TCP 3260) to initiate the attack sequence.\nThe flaw stems from insufficient validation or enforcement of CHAP (Challenge Handshake Authentication Protocol) or mutual authentication mechanisms, enabling an attacker to pose as a legitimate initiator or circumvent the authentication handshake entirely.",
  "technicalDetails": "The vulnerability resides within the Windows iSCSI subsystem, specifically impacting the handling of the authentication phase during the iSCSI session establishment protocol.\niSCSI relies on a challenge-response mechanism, most commonly CHAP, to verify the identity of the initiator before allowing access to the iSCSI target. The root cause of this vulnerability is the improper implementation or enforcement of this authentication handshake, allowing an attacker to manipulate the protocol flow.\nThe exploitation method involves the attacker intercepting or crafting network traffic during the initial login phase of the iSCSI connection. Instead of presenting valid credentials or completing the required bidirectional authentication, the attacker can leverage the weakness in the handshake implementation to force the target to transition into an authenticated session state.\nThe attack flow proceeds as follows: 1. The attacker identifies the network address and port (default 3260) of the Windows iSCSI target. 2. The attacker initiates a standard iSCSI Login Request. 3. When the target responds with an authentication challenge, the attacker provides a malformed or intentionally incomplete response that bypasses the verification logic. 4. Due to the flaw in the authentication module, the target subsystem incorrectly transitions the session to a 'Full Feature' state, assuming the authentication was successful without validation. 5. The attacker is granted unauthorized access to the underlying storage resources mapped to that target.\nThis bypass effectively renders the iSCSI security feature moot, as the target fails to enforce session integrity and identity verification. There are no privilege requirements to initiate this attack, provided the attacker has network access to the target host. Post-exploitation, the attacker gains the ability to interact with the iSCSI target as an authenticated initiator, potentially allowing them to read sensitive data stored on the target, write malicious data, or cause a denial of service if the target is misconfigured to allow destructive commands. The exposure is limited to the network segment where the iSCSI target is reachable, emphasizing the need for strict network segmentation around iSCSI traffic."
}
CVE-2026-73025: Windows iSCSI Authentication Bypass Vulnerability (CRITICAL Severity, CVSS: 9.8) | Sceawere