PT-2005-3077 · Prevx · Prevx Pro

Published

2005-07-05

·

Updated

2008-09-05

·

CVE-2005-2145

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Prevx Pro 2005 version 1.0
Description: The issue concerns a lack of verification of the source of certain messages by the kernel driver, allowing local users to bypass protection. This can be achieved by sending specific messages to the driver, such as an "allow" message, which can bypass a warning message.
Recommendations: For Prevx Pro 2005 version 1.0, consider restricting access to the kernel driver to prevent local users from sending unauthorized messages until a fix is available. As a temporary workaround, avoid using the feature that relies on the kernel driver for message verification until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2145

Affected Products

Prevx Pro