PT-2006-3478 · Ipswitch · Ipswitch Whatsup Professional

Publicado

2006-05-22

·

Atualizado

2018-10-18

·

CVE-2006-2531

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Professional version 2006
Description The issue allows remote attackers to bypass authentication by spoofing the identity of a trusted console. This is achieved by setting the HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
Recommendations For Ipswitch WhatsUp Professional version 2006, consider disabling the use of HTTP headers for user identity verification until a more secure authentication method is implemented. Restrict access to the console to minimize the risk of exploitation. Avoid relying solely on HTTP headers for authentication.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-2531

Produtos afetados

Ipswitch Whatsup Professional