Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2006-2369

Опубликовано: 15 мая 2006
Источник: nvd
CVSS2: 7.5
EPSS Критический

Описание

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vnc:realvnc:4.1.1:*:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.93085
Критический

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 19 лет назад

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

debian
больше 19 лет назад

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink I ...

github
больше 3 лет назад

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

EPSS

Процентиль: 100%
0.93085
Критический

7.5 High

CVSS2

Дефекты

CWE-287