CVE-2012-2606
Last modified
CVE-2012-2606 is a vulnerability of currently unknown severity. The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.. EPSS estimates a 2.07% chance of exploitation in the next 30 days.
Description
The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bradfordnetworks | Network Sentry Appliance Software | <= 5.3 |
| Bradfordnetworks | Network Sentry Appliance | ns500rx |
| Bradfordnetworks | Network Sentry Appliance | ns500x |
References
- http://www.kb.cert.org/vuls/id/709939US Government Resource
- http://www.kb.cert.org/vuls/id/709939US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2012-2606?
How severe is CVE-2012-2606?
How do I fix CVE-2012-2606?
Are you affected by CVE-2012-2606?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
