Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44425

Опубликовано: 12 сент. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
Версия до 6.2.6 (исключая)
cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
Версия от 6.3.0 (включая) до 6.3.3 (исключая)

EPSS

Процентиль: 31%
0.00113
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).

EPSS

Процентиль: 31%
0.00113
Низкий

6.5 Medium

CVSS3

Дефекты

NVD-CWE-noinfo