Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-47250

Опубликовано: 22 нояб. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:m-privacy:mprivacy-tools:*:*:*:*:*:*:*:*
Версия до 4.0.406g (исключая)
cpe:2.3:a:m-privacy:rsbac-policy-tgpro:*:*:*:*:*:*:*:*
Версия до 2.0.159 (исключая)
cpe:2.3:a:m-privacy:tightgatevnc:*:*:*:*:*:*:*:*
Версия до 4.1.2-1 (исключая)

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 8.8
github
около 2 лет назад

In mprivacy-tools before 2.0.406g in m-privacy TightGate-Pro Server, broken Access Control on X11 server sockets allows authenticated attackers (with access to a VNC session) to access the X11 desktops of other users by specifying their DISPLAY ID. This allows complete control of their desktop, including the ability to inject keystrokes and perform a keylogging attack.

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

Дефекты

CWE-276