Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-5008

Опубликовано: 13 июл. 2016
Источник: nvd
CVSS3: 9.8
CVSS2: 4.3
EPSS Низкий

Описание

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:redhat:libvirt:*:*:*:*:*:*:*:*
Версия до 1.3.5 (включая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02817
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 9 лет назад

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

CVSS3: 5.6
redhat
больше 10 лет назад

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

CVSS3: 9.8
debian
около 9 лет назад

libvirt before 2.0.0 improperly disables password checking when the pa ...

suse-cvrf
около 9 лет назад

Security update for libvirt

suse-cvrf
около 9 лет назад

Security update for libvirt

EPSS

Процентиль: 86%
0.02817
Низкий

9.8 Critical

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-284