Vulnerability Note VU#709939
Bradford Network Sentry v5.3 NS500 appliance contains multiple vulnerabilities
Overview
Bradford Network Sentry v5.3 NS500 appliance contains multiple vulnerabilities which could allow an attacker to execute arbitrary code with the privileges of the application.
Description
Bradford Network Sentry v5.3 NS500 appliance contains multiple vulnerabilities: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), CVE-2012-2604 |
Impact
A remote unauthenticated attacker may obtain sensitive information, cause a denial of service condition or execute arbitrary code with the privileges of the application. |
Solution
Update |
Restrict access |
Vendor Information (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Bradford Networks | Affected | 20 Apr 2012 | 05 Jun 2012 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| Temporal | 4.8 | E:POC/RL:OF/RC:UC |
| Environmental | 1.3 | CDP:L/TD:L/CR:ND/IR:ND/AR:ND |
References
- http://cwe.mitre.org/data/definitions/79.html
- http://cwe.mitre.org/data/definitions/352.html
- http://cwe.mitre.org/data/definitions/287.html
- https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IySO
- https://na3.salesforce.com/sfc/#version?selectedDocumentId=06950000000IyBX
- https://na3.salesforce.com/sfc/#version?id=06850000000JDx3
Credit
Thanks to Travis Lee for reporting this vulnerability.
This document was written by Michael Orlando.
Other Information
- CVE IDs: CVE-2012-2604 CVE-2012-2605 CVE-2012-2606
- Date Public: 13 Jun 2012
- Date First Published: 13 Jun 2012
- Date Last Updated: 13 Jun 2012
- Document Revision: 12
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.