PT-2006-3478 · Ipswitch · Ipswitch Whatsup Professional
Published
2006-05-22
·
Updated
2018-10-18
·
CVE-2006-2531
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Ipswitch WhatsUp Professional version 2006
Description
The issue allows remote attackers to bypass authentication by spoofing the identity of a trusted console. This is achieved by setting the HTTP
User-Agent header to "Ipswitch/1.0" and the User-Application header to "NmConsole".Recommendations
For Ipswitch WhatsUp Professional version 2006, consider disabling the use of HTTP headers for user identity verification until a more secure authentication method is implemented. Restrict access to the console to minimize the risk of exploitation. Avoid relying solely on HTTP headers for authentication.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ipswitch Whatsup Professional