Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Microsoft's SQL UDP Info Query

Information

Severity

Severity

Informational

Family

Family

Service detection

CVSSv2 Base

CVSSv2 Base

0.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:N

Created

Created

18 years ago

Modified

Modified

5 years ago

Summary

It is possible to determine the remote MS SQL server version. Microsoft SQL server has a function wherein remote users can query the database server for the version that is being run. The query takes place over the same UDP port which handles the mapping of multiple SQL server instances on the same machine. CAVEAT: It is important to note that, after Version 8.00.194, Microsoft decided not to update this function. This means that the data returned by the SQL ping is inaccurate for newer releases of SQL Server.

Solution

Solution

If you are not running multiple instances of Microsoft SQL Server on the same machine, it is suggested you filter incoming traffic to this port.