Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-17662

Опубликовано: 16 окт. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Критический

Описание

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cybelsoft:thinvnc:1.0:b1:*:*:*:*:*:*

EPSS

Процентиль: 100%
0.93496
Критический

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exists even when authentication is turned on during the deployment of the VNC server. The password for authentication is stored in cleartext in a file that can be read via a ../../ThinVnc.ini directory traversal attack vector.

EPSS

Процентиль: 100%
0.93496
Критический

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22