Vulnerability Description
The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UDP packet that contains an invalid "packet type" field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Enterasys | Netsight Console | 2.1 |
| Enterasys | Netsight Inventory Manager | 2.1 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=506
- http://osvdb.org/34628
- http://secunia.com/advisories/24764PatchVendor Advisory
- http://www.enterasys.com/pub/NetSight/Patches/SP1/NetSight_SP1.pdfVendor Advisory
- http://www.securitytracker.com/id?1017876
- http://www.vupen.com/english/advisories/2007/1271
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=506
- http://osvdb.org/34628
- http://secunia.com/advisories/24764PatchVendor Advisory
- http://www.enterasys.com/pub/NetSight/Patches/SP1/NetSight_SP1.pdfVendor Advisory
- http://www.securitytracker.com/id?1017876
- http://www.vupen.com/english/advisories/2007/1271
FAQ
What is CVE-2007-2344?
CVE-2007-2344 is a vulnerability with a CVSS score of 7.8 (HIGH). The BOOTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, on Windows allows remote attackers to cause a denial of service (daemon crash) via a UD...
How severe is CVE-2007-2344?
CVE-2007-2344 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2007-2344?
Check the references section above for vendor advisories and patch information. Affected products include: Enterasys Netsight Console, Enterasys Netsight Inventory Manager.