CVE-2006-3425
Last modified
CVE-2006-3425 is a vulnerability of currently unknown severity. FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Lumension | Patchlink Update Server | 6.1 | — |
| Lumension | Patchlink Update Server | 6.2.0.181 | — |
| Lumension | Patchlink Update Server | 6.2.0.189 | — |
| Novell | Zenworks | <= 6.2 | Sr1 |
References
- http://secunia.com/advisories/20876Patch, Vendor Advisory
- http://secunia.com/advisories/20878Patch, Vendor Advisory
- http://secunia.com/advisories/20876Patch, Vendor Advisory
- http://secunia.com/advisories/20878Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3425?
How severe is CVE-2006-3425?
How do I fix CVE-2006-3425?
Are you affected by CVE-2006-3425?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
