Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.10674
Category:Service detection
Title:Microsoft's SQL UDP Info Query
Summary:It is possible to determine the remote MS SQL server version.;; Microsoft SQL server has a function wherein remote users can query the database server for the; version that is being run. The query takes place over the same UDP port which handles the; mapping of multiple SQL server instances on the same machine.;; CAVEAT: It is important to note that, after Version 8.00.194, Microsoft decided not to update; this function. This means that the data returned by the SQL ping is inaccurate for newer releases; of SQL Server.
Description:Summary:
It is possible to determine the remote MS SQL server version.

Microsoft SQL server has a function wherein remote users can query the database server for the
version that is being run. The query takes place over the same UDP port which handles the
mapping of multiple SQL server instances on the same machine.

CAVEAT: It is important to note that, after Version 8.00.194, Microsoft decided not to update
this function. This means that the data returned by the SQL ping is inaccurate for newer releases
of SQL Server.

Solution:
If you are not running multiple instances of Microsoft SQL Server
on the same machine, it is suggested you filter incoming traffic to this port.

CVSS Score:
0.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:N

CopyrightCopyright (C) 2005 HD Moore

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.