cvedb.io
CVE-2022-42982
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2022-11-17T05:15:15.440 · Last modified 2026-06-17T05:05:43.043

Summary

BKG Professional NtripCaster 2.0.39 allows querying information over the UDP protocol without authentication. The NTRIP sourcetable is typically quite long (tens of kBs) and can be requested with a packet of only 30 bytes. This presents a vector that can be used for UDP amplification attacks. Normally, only authenticated streaming data will be provided over UDP and not the sourcetable.

Affected products

bund — bkg_professional_ntripcaster

Does this affect you?

Add your gear to cvedb and we'll alert you only when bund ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.