Описание
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:apple:apple_remote_desktop:3.5.2:*:*:*:*:*:*:*
cpe:2.3:a:apple:apple_remote_desktop:3.5.3:*:*:*:*:*:*:*
cpe:2.3:a:apple:apple_remote_desktop:3.6.0:*:*:*:*:*:*:*
EPSS
Процентиль: 65%
0.00493
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310
Связанные уязвимости
github
больше 3 лет назад
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
EPSS
Процентиль: 65%
0.00493
Низкий
4.3 Medium
CVSS2
Дефекты
CWE-310