Описание
UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP address and port number.
Ссылки
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 1201 (включая)
cpe:2.3:a:ultravnc:repeater:*:*:*:*:*:*:*:*
EPSS
Процентиль: 80%
0.01374
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-284
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
UltraVNC Repeater before 1300 does not restrict destination IP addresses or TCP ports, which allows remote attackers to obtain open-proxy functionality by using a :: substring in between the IP address and port number.
EPSS
Процентиль: 80%
0.01374
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-284