SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2012-2606

The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay…

MEDIUM 5.0EPSS 2.07%

Does this matter?

Lower severity and a low EPSS score (2.07%). Track it; it rarely justifies an emergency change on its own.

Description

The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
2.07% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-287
Affected
bradfordnetworks/network sentry appliance software · bradfordnetworks/network sentry appliance
Source
cret@cert.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.