Overview
The Secure Elements Class 5 AVR server fails to validate the source address of messages it receives. This may allow an attacker to forge messages to the server.
Description
Class 5 AVR Secure Elements Class 5 AVR (Automated Vulnerability Remediation) is a security product that monitors and enforces security policies on network assets. Class 5 AVR is now known as C5 EVM (Enterprise Vulnerability Management). The Class 5 AVR software includes both server and client components. |
Impact
A remote, unauthenticated attacker may be able to forge client messages. This can allow an attacker to intercept communications initiated by the server. An attacker may also be able to alter the client information stored by the server. |
Solution
Upgrade or patch |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to the NOAA N-CIRT Lab for reporting this vulnerability.
This document was written by Will Dormann.
Other Information
CVE IDs: | None |
Severity Metric: | 0.87 |
Date Public: | 2006-05-30 |
Date First Published: | 2006-05-30 |
Date Last Updated: | 2006-06-07 03:00 UTC |
Document Revision: | 6 |