CVE-2007-2343
Last modified
CVE-2007-2343 is a vulnerability of currently unknown severity. Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.. EPSS estimates a 3.99% chance of exploitation in the next 30 days.
Description
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Enterasys | Netsight Console | <= 2.1 |
| Enterasys | Netsight Inventory Manager | <= 2.1 |
References
- http://secunia.com/advisories/24764Exploit, Vendor Advisory
- http://secunia.com/advisories/24764Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2343?
How severe is CVE-2007-2343?
How do I fix CVE-2007-2343?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2337Multiple cross-site scripting (XSS) vulnerabilities in Expon…
- CVE-2007-2338Cross-site request forgery (CSRF) vulnerability in include/a…
- CVE-2007-2339Multiple SQL injection vulnerabilities in Phorum before 5.1.…
- CVE-2007-2340Multiple PHP remote file inclusion vulnerabilities in inc/in…
- CVE-2007-2341PHP remote file inclusion vulnerability in suite/index.php i…
- CVE-2007-2342SQL injection vulnerability in error.asp in CreaScripts Crea…
- CVE-2007-2344The BOOTPD component in Enterasys NetSight Console 2.1 and N…
- CVE-2007-2345PHP remote file inclusion vulnerability in include/include_s…
- CVE-2007-2346Multiple PHP remote file inclusion vulnerabilities in PHP-Ge…
- CVE-2007-2347PHP remote file inclusion vulnerability in main/forum/koment…
- CVE-2007-2348mirror --script in lftp before 3.5.9 does not properly quote…
- CVE-2007-2349Cross-site scripting (XSS) vulnerability in Invision Power B…
Are you affected by CVE-2007-2343?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
