Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-24883

Опубликовано: 22 апр. 2022
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a SAM file might be successful for invalid credentials if the server has configured an invalid SAM file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a SAM file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via HashCallback and/or ensure the SAM database path configured is valid and the application has file handles left.

A vulnerability was found in freerdp. This flaw occurs when the server-side authentication against a SAM file might be successful for invalid credentials if the server has configured an invalid SAM file path. This issue exposes an improper authenticating vulnerability.

Отчет

The CVE is just for server functionality, but the server support is completely disabled in RHEL. So RHEL is not affected by this CVE.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2079057freerdp: Server Side Auth Against a SAM File May Succeed for Invalid Creds

EPSS

Процентиль: 73%
0.00763
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 3 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.

CVSS3: 7.4
nvd
больше 3 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.

CVSS3: 7.4
debian
больше 3 лет назад

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). ...

CVSS3: 9.8
fstec
больше 3 лет назад

Уязвимость RDP-сервера FreeRDP, связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти процесс аутентификации

suse-cvrf
больше 3 лет назад

Security update for freerdp

EPSS

Процентиль: 73%
0.00763
Низкий

9.8 Critical

CVSS3