First published: Fri Apr 27 2007(Updated: )
Stack-based buffer overflow in the TFTPD component in Enterasys NetSight Console 2.1 and NetSight Inventory Manager 2.1, and possibly earlier, allows remote attackers to execute arbitrary code via crafted request packets that contain long file names.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Enterasys NetSight Inventory Manager | <=2.1 | |
Enterasys NetSight | <=2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2343 is classified as a high severity vulnerability due to the potential for remote code execution.
To fix CVE-2007-2343, you should update the affected Enterasys NetSight Console and NetSight Inventory Manager to the latest available versions that address this vulnerability.
CVE-2007-2343 affects Enterasys NetSight Console version 2.1 and NetSight Inventory Manager version 2.1, and possibly earlier versions.
Yes, CVE-2007-2343 can be exploited remotely by attackers through specially crafted request packets with long file names.
CVE-2007-2343 allows remote attackers to execute arbitrary code, potentially compromising the affected systems.