PT-2006-3478 · Ipswitch · Ipswitch Whatsup Professional

Published

2006-05-22

·

Updated

2018-10-18

·

CVE-2006-2531

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Ipswitch WhatsUp Professional version 2006
Description The issue allows remote attackers to bypass authentication by spoofing the identity of a trusted console. This is achieved by setting the HTTP User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".
Recommendations For Ipswitch WhatsUp Professional version 2006, consider disabling the use of HTTP headers for user identity verification until a more secure authentication method is implemented. Restrict access to the console to minimize the risk of exploitation. Avoid relying solely on HTTP headers for authentication.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2531

Affected Products

Ipswitch Whatsup Professional