The server is accepting NTLM anonymous credentials.
This allows for authentication bypass to access the underlying application.
https://blog.leakix.net/2022/03/bypassing-ntlm-auth-over-http/
Fingerprint: 40fea8e6a9bd2c3671ce48dbe86f199c98a4427a4a2e1e5a75692ef165113868
Server didn't refuse ANONYMOUS NTLM connection Found NTLM information: Running Windows 10.0 build 20348 MsvAvNbComputerName: WIN-YWF262VGNY6 MsvAvNbDomainName: CVLT MsvAvDNSComputerName: WIN-YWF262VGNY6.CVLT.LOCAL MsvAvDNSDomainName: CVLT.LOCAL MsvAvDNSTreeName: CVLT.LOCAL 200 OK Content-Length: 0 Content-Type: text/html Date: Thu, 10 Oct 2024 13:39:54 GMT Server: Microsoft-IIS/10.0 Www-Authenticate: NTLM