CVE-2012-2606

Bradford Network Sentry <5.3.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

The agent in Bradford Network Sentry before 5.3.3 does not require authentication for messages, which allows remote attackers to trigger the display of arbitrary text on a workstation via a crafted packet to UDP port 4567, as demonstrated by a replay attack.

References (3)

Core 3
Core References
Third Party Advisory, US Government Resource x_refsource_confirm
http://www.kb.cert.org/vuls/id/MAPG-8TJKAF
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/709939

Scores

EPSS 0.0207
EPSS Percentile 79.1%

Details

CWE
CWE-287
Status published
Products (3)
bradfordnetworks/network_sentry_appliance ns500rx
bradfordnetworks/network_sentry_appliance ns500x
bradfordnetworks/network_sentry_appliance_software < 5.3
Published Jun 13, 2012
Tracked Since Feb 18, 2026