This script is Copyright (C) 2008-2014 Tenable Network Security, Inc.
A remote service may be affected by a format string vulnerability.
The remote host is running a Common Management Agent, a component of
the ePolicy Orchestrator system security management solution from
The version of the Common Management Agent on the remote host is
earlier than 126.96.36.1995 and, as such, contains a format string
vulnerability. If configured with a debug level of 8 (its highest
level but not the default), an unauthenticated, remote attacker may be
able to leverage this issue by sending a specially crafted UDP packet
to the agent broadcast port to crash the service or even execute
arbitrary code on the affected host.
Note that Nessus has not looked at the setting of the LogLevel, only
the version number in the agent's banner, so it may not actually be
vulnerable to attack.
See also :
Apply Hotfix BZ398370 Build 595 for Common Management Agent 3.6.0
Risk factor :
Medium / CVSS Base Score : 5.1
CVSS Temporal Score : 4.4
Public Exploit Available : true
Family: Web Servers
Nessus Plugin ID: 31732 ()
Bugtraq ID: 28228
CVE ID: CVE-2008-1357
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.