PT-2022-26692 · Bkg · Bkg Professional Ntripcaster

Published

2022-11-17

·

Updated

2025-04-30

·

CVE-2022-42982

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BKG Professional NtripCaster version 2.0.39
Description The issue allows querying information over the UDP protocol without authentication. The NTRIP sourcetable, which is typically quite long, can be requested with a small packet, presenting a vector for UDP amplification attacks. Normally, only authenticated streaming data is provided over UDP.
Recommendations For version 2.0.39, consider restricting access to the UDP protocol to prevent unauthorized queries of the NTRIP sourcetable until a patch is available. As a temporary workaround, disabling the ability to request the sourcetable over UDP can help minimize the risk of UDP amplification attacks.

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-42982

Affected Products

Bkg Professional Ntripcaster