PT-2006-7086 · Mandiant · Mandiant First Response

Brian Reilly

·

Publicado

2006-12-20

·

Atualizado

2018-10-17

·

CVE-2006-6477

CVSS v2.0

2.4

Baixa

VetorAV:L/AC:H/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Mandiant First Response (MFR) versions prior to 1.1.1
Description The issue allows local users to modify requests and responses between a client and an agent by hijacking an HTTP daemon and conducting a man-in-the-middle (MITM) attack when run in daemon mode and configured to use only HTTP.
Recommendations For versions prior to 1.1.1, update to version 1.1.1 or later to resolve the issue. As a temporary workaround, consider disabling the HTTP daemon mode or configuring it to use a secure protocol instead of HTTP to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6477

Produtos afetados

Mandiant First Response