CVE-2022-42982

HIGH

BKG Professional NtripCaster < 2.0.39 - Unauthenticated UDP Amplification via NTRIP Sourcetable Query

Title source: llm
STIX 2.1

Description

BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.

References (2)

Core 2
Core References
Third Party Advisory
https://cve.mahi.be/bkg_ntrip_udp/
Product, Vendor Advisory
https://igs.bkg.bund.de/ntrip/bkgcaster

Scores

CVSS v3 7.5
EPSS 0.0066
EPSS Percentile 46.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
bund/bkg_professional_ntripcaster < 2.0.39
Published Nov 17, 2022
Tracked Since Feb 18, 2026