CVE-2006-2369
Last modified
CVE-2006-2369 is a vulnerability of currently unknown severity. RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.. EPSS estimates a 91.52% chance of exploitation in the next 30 days.
Description
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vnc | Realvnc | 4.1.1 |
References
- http://secunia.com/advisories/20107Patch, Vendor Advisory
- http://secunia.com/advisories/20109Patch, Vendor Advisory
- http://secunia.com/advisories/20789Vendor Advisory
- http://securitytracker.com/id?1016083Exploit, Patch
- http://www.kb.cert.org/vuls/id/117929Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/17978Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1790Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1821Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2492Vendor Advisory
- http://secunia.com/advisories/20107Patch, Vendor Advisory
- http://secunia.com/advisories/20109Patch, Vendor Advisory
- http://secunia.com/advisories/20789Vendor Advisory
- http://securitytracker.com/id?1016083Exploit, Patch
- http://www.kb.cert.org/vuls/id/117929Patch, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/17978Exploit, Patch
- http://www.vupen.com/english/advisories/2006/1790Vendor Advisory
- http://www.vupen.com/english/advisories/2006/1821Vendor Advisory
- http://www.vupen.com/english/advisories/2006/2492Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-2369?
How severe is CVE-2006-2369?
How do I fix CVE-2006-2369?
Are you affected by CVE-2006-2369?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
