Количество 4
Количество 4
CVE-2026-91949
[GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS]
CVE-2026-91949
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
CVE-2026-91949
FreeRDP server versions before 3.31.0 contain a protocol negotiation b ...
GHSA-hcpv-8ff6-4xx8
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-91949 [GHSA-x7v6-xfx3-52j6: FreeRDP server continues after negotiation failure and dispatches a failure code as RDSTLS] | CVSS3: 9.3 | 0% Низкий | 4 дня назад | |
CVE-2026-91949 FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions. | CVSS3: 9.3 | 0% Низкий | 4 дня назад | |
CVE-2026-91949 FreeRDP server versions before 3.31.0 contain a protocol negotiation b ... | CVSS3: 9.3 | 0% Низкий | 4 дня назад | |
GHSA-hcpv-8ff6-4xx8 FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass vulnerability that allows unauthenticated attackers to establish RDSTLS connections despite server policy disabling them. Attackers can send incompatible protocol requests, receive negotiation failures, then complete TLS handshake and enter RDSTLS to bypass pre-authentication transport restrictions. | CVSS3: 9.3 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу