Описание
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter MaxLoginRetry in /etc/xrdp/sesman.ini. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | not-affected | 0.10.1-4.1 |
| esm-apps-legacy/xenial | not-affected | code not present |
| esm-apps/bionic | released | 0.9.5-2ubuntu0.1~esm3 |
| esm-apps/focal | released | 0.9.12-1ubuntu0.1+esm2 |
| esm-apps/jammy | released | 0.9.17-2ubuntu3+esm2 |
| esm-apps/noble | released | 0.9.24-4ubuntu0.1~esm1 |
| esm-apps/resolute | not-affected | 0.10.1-4.1 |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| esm-infra-legacy/trusty | not-affected | code not present |
| focal | ignored | end of standard support, was needs-triage |
Показывать по
EPSS
7.2 High
CVSS3
Связанные уязвимости
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have ...
EPSS
7.2 High
CVSS3