Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-4478

Опубликовано: 16 мая 2025
Источник: nvd
CVSS3: 7.1
CVSS3: 6.5
EPSS Низкий

Описание

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.16.0 (исключая)
Конфигурация 2
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

EPSS

Процентиль: 25%
0.00083
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-476

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 месяцев назад

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

CVSS3: 7.1
redhat
6 месяцев назад

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

CVSS3: 7.1
debian
6 месяцев назад

A flaw was found in the FreeRDP used by Anaconda's remote install feat ...

rocky
около 1 месяца назад

Moderate: freerdp security update

CVSS3: 7.1
github
6 месяцев назад

A flaw was found in the gnome-remote-desktop used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

EPSS

Процентиль: 25%
0.00083
Низкий

7.1 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-476