PT-2006-6431 · Highwall · Highwall Enterprise+1
Published
2006-11-06
·
Updated
2018-10-17
·
CVE-2006-5743
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Highwall Enterprise version 4.0.2.11045
Highwall Endpoint version 4.0.2.11045
Description:
The issue allows remote attackers to inject arbitrary web script or HTML via various vectors, including an Access Point with a crafted SSID, the name of the sensor WIDS, or the name of the Highwall EndPoint workstation.
Recommendations:
For Highwall Enterprise version 4.0.2.11045, consider restricting access to the management interface until a fix is available.
For Highwall Endpoint version 4.0.2.11045, avoid using crafted SSID names or other potentially malicious input in the management interface until the issue is resolved.
As a temporary workaround, consider disabling the management interface or restricting its access to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Highwall Endpoint
Highwall Enterprise