PT-2005-3077 · Prevx · Prevx Pro
Published
2005-07-05
·
Updated
2008-09-05
·
CVE-2005-2145
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Prevx Pro 2005 version 1.0
Description:
The issue concerns a lack of verification of the source of certain messages by the kernel driver, allowing local users to bypass protection. This can be achieved by sending specific messages to the driver, such as an "allow" message, which can bypass a warning message.
Recommendations:
For Prevx Pro 2005 version 1.0, consider restricting access to the kernel driver to prevent local users from sending unauthorized messages until a fix is available. As a temporary workaround, avoid using the feature that relies on the kernel driver for message verification until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Prevx Pro