CVE-2006-3838
Last modified
CVE-2006-3838 is a vulnerability of currently unknown severity. Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).. EPSS estimates a 73.15% chance of exploitation in the next 30 days.
Description
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eiqnetworks | Enterprise Security Analyzer | <= 2.4.0 |
References
- http://secunia.com/advisories/21211Vendor Advisory
- http://secunia.com/advisories/21213Vendor Advisory
- http://secunia.com/advisories/21214Vendor Advisory
- http://secunia.com/advisories/21215Vendor Advisory
- http://secunia.com/advisories/21217Vendor Advisory
- http://secunia.com/advisories/21218Vendor Advisory
- http://www.kb.cert.org/vuls/id/513068US Government Resource
- http://www.vupen.com/english/advisories/2006/2985Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3006Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3007Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3008Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3009Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3010Vendor Advisory
- http://secunia.com/advisories/21211Vendor Advisory
- http://secunia.com/advisories/21213Vendor Advisory
- http://secunia.com/advisories/21214Vendor Advisory
- http://secunia.com/advisories/21215Vendor Advisory
- http://secunia.com/advisories/21217Vendor Advisory
- http://secunia.com/advisories/21218Vendor Advisory
- http://www.kb.cert.org/vuls/id/513068US Government Resource
- http://www.vupen.com/english/advisories/2006/2985Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3006Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3007Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3008Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3009Vendor Advisory
- http://www.vupen.com/english/advisories/2006/3010Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-3838?
How severe is CVE-2006-3838?
How do I fix CVE-2006-3838?
Are you affected by CVE-2006-3838?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
