Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-32105

Опубликовано: 17 апр. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generates signatures, the receiving logic lacks the necessary implementation to validate the 8-byte integrity signature, causing it to be silently ignored. An unauthenticated attacker with man-in-the-middle (MITM) capabilities can exploit this missing check to modify encrypted traffic in transit without detection. It does not affect connections where the TLS security layer is enforced. This issue has been fixed in version 0.10.6. If users are unable to immediately upgrade, they should configure xrdp.ini to enforce TLS security (security_layer=tls) to ensure end-to-end integrity.

A flaw was found in xrdp, an open-source Remote Desktop Protocol (RDP) server. When using the "Classic RDP Security" layer, xrdp fails to verify the Message Authentication Code (MAC) signature of encrypted RDP packets. This oversight allows an unauthenticated attacker with man-in-the-middle (MITM) capabilities to modify encrypted traffic as it travels between the client and server without being detected, compromising data integrity. This vulnerability does not affect connections where the Transport Layer Security (TLS) security layer is enforced.

Отчет

This vulnerability in xrdp compromises data integrity when the "Classic RDP Security" layer is in use, allowing an unauthenticated man-in-the-middle attacker to modify encrypted RDP traffic without detection. Connections configured to enforce the TLS security layer are not affected by this flaw. This vulnerability doesn't affect any supported Red Hat products.

Меры по смягчению последствий

Configure xrdp to enforce TLS security. Edit /etc/xrdp/xrdp.ini and set security_layer=tls in the [Globals] section. A restart of the xrdp service is required for the changes to take effect.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-347
https://bugzilla.redhat.com/show_bug.cgi?id=2459272xrdp: xrdp: Data integrity compromised due to missing MAC signature verification in Classic RDP Security

EPSS

Процентиль: 7%
0.00174
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generates signatures, the receiving logic lacks the necessary implementation to validate the 8-byte integrity signature, causing it to be silently ignored. An unauthenticated attacker with man-in-the-middle (MITM) capabilities can exploit this missing check to modify encrypted traffic in transit without detection. It does not affect connections where the TLS security layer is enforced. This issue has been fixed in version 0.10.6. If users are unable to immediately upgrade, they should configure xrdp.ini to enforce TLS security (security_layer=tls) to ensure end-to-end integrity.

CVSS3: 7.7
nvd
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classic RDP Security" layer. While the sender correctly generates signatures, the receiving logic lacks the necessary implementation to validate the 8-byte integrity signature, causing it to be silently ignored. An unauthenticated attacker with man-in-the-middle (MITM) capabilities can exploit this missing check to modify encrypted traffic in transit without detection. It does not affect connections where the TLS security layer is enforced. This issue has been fixed in version 0.10.6. If users are unable to immediately upgrade, they should configure xrdp.ini to enforce TLS security (security_layer=tls) to ensure end-to-end integrity.

CVSS3: 7.7
debian
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, xrdp do ...

CVSS3: 10
fstec
4 месяца назад

Уязвимость сервера XRDP, связанная с неправильной проверкой значения целостности, позволяющая нарушителю выполнить атаку типа «человек посередине»

EPSS

Процентиль: 7%
0.00174
Низкий

5.9 Medium

CVSS3