Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73241

Опубликовано: 11 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.

A vulnerability in FreeRDP's server-side RDSTLS allows remote, unauthenticated attackers to bypass authentication. By sending a crafted capabilities PDU instead of the expected authentication request, an attacker can gain an authenticated session without valid credentials.

Отчет

An Important flaw in FreeRDP 3.0+ allows remote, unauthenticated attackers to bypass authentication and gain session access. This vulnerability only affects servers explicitly configured with the non-default RdstlsSecurity = TRUE setting. Because RDSTLS was introduced in version 3.0, RHEL 9 and older releases are completely unaffected.

Меры по смягчению последствий

Do not enable RDSTLS server authentication (RdstlsSecurity); it is disabled by default. If FreeRDP is deployed as an RDP server with RDSTLS enabled, disable RdstlsSecurity

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2514349FreeRDP: FreeRDP: Authentication bypass via incorrect RDSTLS PDU handling

EPSS

Процентиль: 31%
0.00382
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
17 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.

nvd
17 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.

debian
17 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

EPSS

Процентиль: 31%
0.00382
Низкий

7.5 High

CVSS3