PT-2022-26692 · Bkg · Bkg Professional Ntripcaster
Published
2022-11-17
·
Updated
2025-04-30
·
CVE-2022-42982
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BKG Professional NtripCaster version 2.0.39
Description
The issue allows querying information over the UDP protocol without authentication. The NTRIP sourcetable, which is typically quite long, can be requested with a small packet, presenting a vector for UDP amplification attacks. Normally, only authenticated streaming data is provided over UDP.
Recommendations
For version 2.0.39, consider restricting access to the UDP protocol to prevent unauthorized queries of the NTRIP sourcetable until a patch is available. As a temporary workaround, disabling the ability to request the sourcetable over UDP can help minimize the risk of UDP amplification attacks.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bkg Professional Ntripcaster