5
CVE-2012-2606
- EPSS 2.07%
- Veröffentlicht 13.06.2012 15:55:01
- Zuletzt bearbeitet 16.06.2026 23:41:45
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bradfordnetworks ≫ Network Sentry Appliance Software Version <= 5.3
Bradfordnetworks ≫ Network Sentry Appliance Versionns500rx
Bradfordnetworks ≫ Network Sentry Appliance Versionns500x
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.07% | 0.79 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://www.kb.cert.org/vuls/id/709939
http://www.kb.cert.org/vuls/id/MAPG-8TJKAF
https://na3.salesforce.com/sfc/#version?id=06850000000JDx3