5
CVE-2012-2606
- EPSS 5.81%
- Veröffentlicht 13.06.2012 15:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle cret@cert.org
- CVE-Watchlists
- Unerledigt
The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bradfordnetworks ≫ Network Sentry Appliance Software Version <= 5.3
Bradfordnetworks ≫ Network Sentry Appliance Versionns500rx
Bradfordnetworks ≫ Network Sentry Appliance Versionns500x
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.81% | 0.902 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.