VYPR
Unrated severityNVD Advisory· Published Jul 7, 2006· Updated Apr 16, 2026

CVE-2006-3425

CVE-2006-3425

Description

FastPatch for (a) PatchLink Update Server (PLUS) before 6.1 P1 and 6.2.x before 6.2 SR1 P1, and (b) Novell ZENworks 6.2 SR1 and earlier, does not require authentication for dagent/proxyreg.asp, which allows remote attackers to list, add, or delete PatchLink Distribution Point (PDP) proxy servers via modified (1) List, (2) Proxy, or (3) Delete parameters.

Affected products

4
  • cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:lumension:patchlink_update_server:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:lumension:patchlink_update_server:6.2.0.181:*:*:*:*:*:*:*
    • cpe:2.3:a:lumension:patchlink_update_server:6.2.0.189:*:*:*:*:*:*:*
  • cpe:2.3:a:novell:zenworks:*:sr1:*:*:*:*:*:*
    Range: <=6.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.