Описание
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Ссылки
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Vendor Advisory
- Third Party AdvisoryUS Government Resource
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.3.3 (включая)
cpe:2.3:a:att:winvnc:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.0139
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
больше 3 лет назад
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
EPSS
Процентиль: 80%
0.0139
Низкий
7.5 High
CVSS2
Дефекты
NVD-CWE-Other