PT-2006-7086 · Mandiant · Mandiant First Response
Brian Reilly
·
Publicado
2006-12-20
·
Atualizado
2018-10-17
·
CVE-2006-6477
CVSS v2.0
2.4
Baixa
| Vetor | AV:L/AC:H/Au:S/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Mandiant First Response (MFR) versions prior to 1.1.1
Description
The issue allows local users to modify requests and responses between a client and an agent by hijacking an HTTP daemon and conducting a man-in-the-middle (MITM) attack when run in daemon mode and configured to use only HTTP.
Recommendations
For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider disabling the HTTP daemon mode or configuring it to use a secure protocol instead of HTTP to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mandiant First Response