SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6477

FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a…

LOW 2.4EPSS 0.26%

Does this matter?

Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.

Description

FRAgent.exe in Mandiant First Response (MFR) before 1.1.1, when run in daemon mode and configured to use only HTTP, allows local users to modify requests and responses between a client and an agent by hijacking an HTTP FRAgent daemon and conducting a man-in-the-middle (MITM) attack.

CVSS 2.0
2.4 LOWAV:L/AC:H/Au:S/C:N/I:P/A:P
EPSS
0.26% probability · 17th percentile
CISA KEV
Not listed
Affected
mandiant/first response
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.