BKG Professional NtripCaster 2.0.39 allows querying...
High severity
Unreviewed
Published
Nov 17, 2022
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Nov 17, 2022
Published to the GitHub Advisory Database
Nov 17, 2022
Last updated
Feb 1, 2023
BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.
References