CVE-2006-6476
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a…
Does this matter?
Lower severity and a low EPSS score (0.27%). Track it; it rarely justifies an emergency change on its own.
Description
FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and when the agent is bound to 0.0.0.0 (all interfaces), opens sockets in non-exclusive mode, which allows local users to hijack the socket, and capture data or cause a denial of service (loss of daemon operation).
- CVSS 2.0
- 2.4 LOWAV:L/AC:H/Au:S/C:P/I:N/A:P
- EPSS
- 0.27% probability · 19th percentile
- CISA KEV
- Not listed
- Affected
- mandiant/first response
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23393Patch, Vendor Advisory
- http://securityreason.com/securityalert/2052
- http://securitytracker.com/id?1017394Patch
- http://www.mandiant.com/firstresponse.htm
- http://www.securityfocus.com/archive/1/454712/100/0/threaded
- http://www.securityfocus.com/bid/21548Patch
- http://www.symantec.com/enterprise/research/SYMSA-2006-013.txtPatch
- http://www.vupen.com/english/advisories/2006/5061
- http://secunia.com/advisories/23393Patch, Vendor Advisory
- http://securityreason.com/securityalert/2052
- http://securitytracker.com/id?1017394Patch
- http://www.mandiant.com/firstresponse.htm
- http://www.securityfocus.com/archive/1/454712/100/0/threaded
- http://www.securityfocus.com/bid/21548Patch
- http://www.symantec.com/enterprise/research/SYMSA-2006-013.txtPatch
- http://www.vupen.com/english/advisories/2006/5061
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.