CVE-2006-3838 (CNNVD-200607-454)

CRITICAL 有利用代码
中文标题:
eIQnetworks ESA EnterpriseSecurityAnalyzer.exe LICMGR_ADDLICENSE命令远程缓冲区溢
英文标题:
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0...
CVSS分数: 10.0
发布时间: 2006-07-27 01:00:00
漏洞类型: 授权问题
状态: PUBLISHED
数据质量分数: 0.40
数据版本: v9
漏洞描述
中文描述:

eIQnetworks Enterprise Security Analyzer(ESA)是一款企业级的安全管理平台。 eIQnetworks ESA中默认绑定到TCP/10616端口的EnterpriseSecurityAnalyzer.exe中存在缓冲区溢出漏洞,远程攻击者可能利用此漏洞在服务器上执行任意指令。 EnterpriseSecurityAnalyzer.exe在处理传送给LICMGR_ADDLICENSE命令的超长参数时可能会触发栈溢出,导致执行任意指令。 <**>

英文描述:

Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).

CWE类型:
CWE-119
标签:
remote windows Metasploit OSVDB-27528 OSVDB-27526 ri0t Kevin Finisterre
受影响产品
厂商 产品 版本 版本范围 平台 CPE
eiqnetworks enterprise_security_analyzer * - - cpe:2.3:a:eiqnetworks:enterprise_security_analyzer:*:*:*:*:*:*:*:*
解决方案
中文解决方案:
(暂无数据)
英文解决方案:
(暂无数据)
临时解决方案:
(暂无数据)
参考链接
无标题 x_refsource_MISC
cve.org
访问
19167 vdb-entry
cve.org
访问
无标题 x_refsource_CONFIRM
cve.org
访问
21218 third-party-advisory
cve.org
访问
ADV-2006-3007 vdb-entry
cve.org
访问
27526 vdb-entry
cve.org
访问
eiqnetworks-esa-syslog-string-bo(27950) vdb-entry
cve.org
访问
21217 third-party-advisory
cve.org
访问
27527 vdb-entry
cve.org
访问
1016580 vdb-entry
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
19163 vdb-entry
cve.org
访问
ADV-2006-2985 vdb-entry
cve.org
访问
20060725 TSRT-06-04: eIQnetworks Enterprise Security Analyzer Topology Server Buffer Overflow Vulnerability mailing-list
cve.org
访问
21215 third-party-advisory
cve.org
访问
20060725 ZDI-06-024: eIQNetworks Enterprise Security Analyzer License Manager Buffer Overflow Vulnerability mailing-list
cve.org
访问
ADV-2006-3008 vdb-entry
cve.org
访问
eiqnetworks-esa-topology-bo(27953) vdb-entry
cve.org
访问
27528 vdb-entry
cve.org
访问
21211 third-party-advisory
cve.org
访问
19164 vdb-entry
cve.org
访问
VU#513068 third-party-advisory
cve.org
访问
20060725 TSRT-06-03: eIQnetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerabilities mailing-list
cve.org
访问
20060808 TSRT-06-07: eIQnetworks Enterprise Security Analyzer Monitoring Agent Buffer Overflow Vulnerabilities mailing-list
cve.org
访问
20060725 ZDI-06-023: eIQNetworks Enterprise Security Analyzer Syslog Server Buffer Overflow Vulnerability mailing-list
cve.org
访问
ADV-2006-3006 vdb-entry
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
21214 third-party-advisory
cve.org
访问
19165 vdb-entry
cve.org
访问
27525 vdb-entry
cve.org
访问
ADV-2006-3010 vdb-entry
cve.org
访问
eiqnetworks-esa-licensemanager-bo(27952) vdb-entry
cve.org
访问
eiqnetworks-esa-syslog-command-bo(27951) vdb-entry
cve.org
访问
21213 third-party-advisory
cve.org
访问
ADV-2006-3009 vdb-entry
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
无标题 x_refsource_MISC
cve.org
访问
eiqnetworks-esa-monitoring-bo(27954) vdb-entry
cve.org
访问
ExploitDB EDB-16438 EXPLOIT
exploitdb
访问
Download Exploit EDB-16438 EXPLOIT
exploitdb
访问
CVE Reference: CVE-2006-3838 ADVISORY
cve.org
访问
ExploitDB EDB-16451 EXPLOIT
exploitdb
访问
Download Exploit EDB-16451 EXPLOIT
exploitdb
访问
ExploitDB EDB-2074 EXPLOIT
exploitdb
访问
Download Exploit EDB-2074 EXPLOIT
exploitdb
访问
ExploitDB EDB-2075 EXPLOIT
exploitdb
访问
Download Exploit EDB-2075 EXPLOIT
exploitdb
访问
ExploitDB EDB-2080 EXPLOIT
exploitdb
访问
Download Exploit EDB-2080 EXPLOIT
exploitdb
访问
ExploitDB EDB-2140 EXPLOIT
exploitdb
访问
Download Exploit EDB-2140 EXPLOIT
exploitdb
访问
CVSS评分详情
10.0
CRITICAL
CVSS向量: AV:N/AC:L/Au:N/C:C/I:C/A:C
CVSS版本: 2.0
机密性
COMPLETE
完整性
COMPLETE
可用性
COMPLETE
时间信息
发布时间:
2006-07-27 01:00:00
修改时间:
2024-08-07 18:48:39
创建时间:
2025-11-11 15:32:36
更新时间:
2026-01-19 09:41:50
利用信息
此漏洞有可利用代码!
利用代码数量: 6
利用来源:
未知 未知 未知 未知 未知 未知
数据源详情
数据源 记录ID 版本 提取时间
CVE cve_CVE-2006-3838 2025-11-11 15:17:44 2025-11-11 07:32:36
NVD nvd_CVE-2006-3838 2025-11-11 14:51:50 2025-11-11 07:41:21
CNNVD cnnvd_CNNVD-200607-454 2025-11-11 15:08:52 2025-11-11 07:49:09
EXPLOITDB exploitdb_EDB-16438 2025-11-11 15:05:55 2025-11-11 08:11:00
EXPLOITDB exploitdb_EDB-16451 2025-11-11 15:05:55 2025-11-11 08:11:01
EXPLOITDB exploitdb_EDB-2074 2025-11-11 15:05:55 2025-11-11 08:15:50
EXPLOITDB exploitdb_EDB-2075 2025-11-11 15:05:55 2025-11-11 08:15:51
EXPLOITDB exploitdb_EDB-2080 2025-11-11 15:05:55 2025-11-11 08:15:53
EXPLOITDB exploitdb_EDB-2140 2025-11-11 15:05:55 2025-11-11 08:16:18
版本与语言
当前版本: v9
主要语言: EN
支持语言:
EN ZH
其他标识符:
:
:
:
:
:
:
:
:
:
:
:
:
安全公告
暂无安全公告信息
变更历史
v9 EXPLOITDB
2025-11-11 16:16:18
references_count: 49 → 51
查看详细变更
  • references_count: 49 -> 51
v8 EXPLOITDB
2025-11-11 16:15:53
references_count: 47 → 49; tags_count: 6 → 7
查看详细变更
  • references_count: 47 -> 49
  • tags_count: 6 -> 7
v7 EXPLOITDB
2025-11-11 16:15:51
references_count: 45 → 47
查看详细变更
  • references_count: 45 -> 47
v6 EXPLOITDB
2025-11-11 16:15:50
references_count: 43 → 45; tags_count: 5 → 6
查看详细变更
  • references_count: 43 -> 45
  • tags_count: 5 -> 6
v5 EXPLOITDB
2025-11-11 16:11:01
references_count: 41 → 43; tags_count: 4 → 5
查看详细变更
  • references_count: 41 -> 43
  • tags_count: 4 -> 5
v4 EXPLOITDB
2025-11-11 16:11:00
references_count: 38 → 41; tags_count: 0 → 4; data_sources: ['cnnvd', 'cve', 'nvd'] → ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
  • references_count: 38 -> 41
  • tags_count: 0 -> 4
  • data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
v3 CNNVD
2025-11-11 15:49:09
vulnerability_type: 未提取 → 授权问题; cnnvd_id: 未提取 → CNNVD-200607-454; data_sources: ['cve', 'nvd'] → ['cnnvd', 'cve', 'nvd']
查看详细变更
  • vulnerability_type: 未提取 -> 授权问题
  • cnnvd_id: 未提取 -> CNNVD-200607-454
  • data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
v2 NVD
2025-11-11 15:41:21
severity: SeverityLevel.MEDIUM → SeverityLevel.CRITICAL; cvss_score: 未提取 → 10.0; cvss_vector: NOT_EXTRACTED → AV:N/AC:L/Au:N/C:C/I:C/A:C; cvss_version: NOT_EXTRACTED → 2.0; affected_products_count: 0 → 1; data_sources: ['cve'] → ['cve', 'nvd']
查看详细变更
  • severity: SeverityLevel.MEDIUM -> SeverityLevel.CRITICAL
  • cvss_score: 未提取 -> 10.0
  • cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:C/I:C/A:C
  • cvss_version: NOT_EXTRACTED -> 2.0
  • affected_products_count: 0 -> 1
  • data_sources: ['cve'] -> ['cve', 'nvd']