CVE-2006-3838

eIQnetworks Enterprise Security Analyzer < 2.4.0 - Remote Code Execution via Multiple Buffer Overflows

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 8 public exploits for CVE-2006-3838. PoCs published by Metasploit, ri0t, Kevin Finisterre, including Metasploit module exploits/windows/misc/eiqnetworks_esa.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) via the DELETEDEVICE command. It sends a maliciously crafted payload to trigger the vulnerability, leading to remote code execution on vulnerable Windows systems.

Description

Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).

Exploits (8)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16438

This exploit targets a stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) via the DELETEDEVICE command. It sends a maliciously crafted payload to trigger the vulnerability, leading to remote code execution on vulnerable Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: eIQNetworks Enterprise Security Analyzer v2.1.13
No auth needed
Prerequisites: Network access to the target system on port 10628 · Vulnerable version of eIQNetworks ESA
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16451

This is a Metasploit module exploiting a stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer via the LICMGR_ADDLICENSE command. It targets multiple Windows versions and OEM variants, delivering a payload to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: eIQNetworks Enterprise Security Analyzer v2.1.13 and OEM variants
No auth needed
Prerequisites: Network access to the target on port 10616
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ri0t · pythonremotewindows
https://www.exploit-db.com/exploits/2140

This exploit targets a buffer overflow in the LICENCE_MANAGER field of EiQ Networks Enterprise Security Analyzer and related OEM products. It sends a crafted payload to trigger a SEH-based overflow, leading to remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EiQ Networks Enterprise Security Analyzer (and OEM variants like Astaro Report Manager, Fortinet FortiReporter, etc.)
No auth needed
Prerequisites: Network access to the target system on port 10616
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Kevin Finisterre · perlremotewindows
https://www.exploit-db.com/exploits/2080

This exploit targets a buffer overflow vulnerability in eiQnetworks Security Analyzer products. It sends a maliciously crafted LICMGR_ADDLICENSE request to port 10616, triggering a bind shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: eiQnetworks Security Analyzer (multiple versions)
No auth needed
Prerequisites: Network access to target · Target software running on port 10616
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ri0t · pythonremotewindows
https://www.exploit-db.com/exploits/2075

This exploit targets a buffer overflow in the EIQ License Manager (CVE-2006-3838) by sending a maliciously crafted LICMGR_ADDLICENSE request with a 494-byte payload. It includes SEH-based exploitation for Windows 2000, XP, and Server 2003.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EIQ Networks License Manager (version not specified)
No auth needed
Prerequisites: Network access to the target's port 10616
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by ri0t · pythonremotewindows
https://www.exploit-db.com/exploits/2074

This exploit targets a buffer overflow in the EIQ License Manager (CVE-2006-3838) by sending a maliciously crafted LICMGR_ADDLICENSE request with a 1262-byte payload. It includes SEH-based exploitation for Windows 2000, XP, and Server 2003.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EIQ Networks License Manager (versions using port 10616)
No auth needed
Prerequisites: Network access to target port 10616 · Target OS and version matching one of the provided addresses
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/eiqnetworks_esa.rb

This Metasploit module exploits a stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer via the LICMGR_ADDLICENSE command. It sends a crafted payload to trigger the vulnerability, leading to remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: eIQNetworks Enterprise Security Analyzer v2.1.13 and OEM variants
No auth needed
Prerequisites: Network access to the target on port 10616
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/misc/eiqnetworks_esa_topology.rb

This Metasploit module exploits a stack-based buffer overflow in eIQnetworks Enterprise Security Analyzer (ESA) via a maliciously crafted DELETEDEVICE command. The exploit targets the Topology server on port 10628, leveraging a long argument to trigger the overflow and execute arbitrary code.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: eIQnetworks Enterprise Security Analyzer v2.1.13
No auth needed
Prerequisites: Network access to the target system on port 10628 · Vulnerable version of eIQnetworks ESA installed
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (38)

Core 38
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27950
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27953
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19167
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21218
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3007
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27526
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21217
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27527
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016580
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19163
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2985
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441198/100/0/threaded
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21215
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441195/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3008
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27528
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21211
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19164
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/513068
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441200/100/0/threaded
Various Sources mailing-list x_refsource_bugtraq
http://archive.cert.uni-stuttgart.de/bugtraq/2006/08/msg00152.html
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/441197/100/0/threaded
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3006
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21214
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/19165
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/27525
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3010
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27952
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27951
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/21213
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/3009
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-06-023.html
Third Party Advisory x_refsource_misc
http://www.zerodayinitiative.com/advisories/ZDI-06-024.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27954

Scores

EPSS 0.7153
EPSS Percentile 98.8%

Details

CWE
CWE-119
Status published
Products (1)
eiqnetworks/enterprise_security_analyzer < 2.4.0
Published Jul 27, 2006
Tracked Since Feb 18, 2026