CVE-2006-3838 describes multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) versions prior to 2.5.0, impacting various rebranded products like Sidewinder and FortiReporter. These vulnerabilities, primarily in the Syslog daemon, Topology server, License Manager, and Monitoring agent, allow unauthenticated remote attackers to execute arbitrary code by sending overly long commands. With a CVSS score of 10.0, this critical vulnerability poses a severe risk of complete system compromise due to its network-based attack vector and low complexity. While not on the KEV catalog, public Metasploit modules and ExploitDB entries confirm readily available exploit code, though community discussion and media coverage remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.0CPE matchmatch criteria | cpe:2.3:a:eiqnetworks:enterprise_security_analyzer:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.