Overview
Bradford Network Sentry v5.3 NS500 appliance contains multiple vulnerabilities which could allow an attacker to execute arbitrary code with the privileges of the application.
Description
Bradford Network Sentry v5.3 NS500 appliance contains multiple vulnerabilities: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CVE-2012-2604 |
Impact
A remote unauthenticated attacker may obtain sensitive information, cause a denial of service condition or execute arbitrary code with the privileges of the application. |
Solution
Update |
Restrict access |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Temporal | 4.8 | E:POC/RL:OF/RC:UC |
Environmental | 1.3 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/287.html
- https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IySO
- https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IyBX
- https://na3.salesforce.com/sfc/#version?id=06850000000JDx3
Acknowledgements
Thanks to Travis Lee for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
CVE IDs: | CVE-2012-2604, CVE-2012-2605, CVE-2012-2606 |
Date Public: | 2012-06-13 |
Date First Published: | 2012-06-13 |
Date Last Updated: | 2012-06-13 11:55 UTC |
Document Revision: | 12 |