PT-2006-6432 · Highwall · Highwall Enterprise+1

Published

2006-11-06

·

Updated

2018-10-17

·

CVE-2006-5744

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Highwall Enterprise version 4.0.2.11045 Highwall Endpoint version 4.0.2.11045
Description: The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via an Access Point with a crafted SSID or through unspecified vectors related to a malicious system operator.
Recommendations: For Highwall Enterprise version 4.0.2.11045, consider restricting access to the management interface to minimize the risk of exploitation. For Highwall Endpoint version 4.0.2.11045, avoid using crafted SSIDs for Access Points until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-5744

Affected Products

Highwall Endpoint
Highwall Enterprise