CVE-2006-2369
EPSS 91.5%
Description
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
How to fix CVE-2006-2369
To remediate CVE-2006-2369, upgrade the affected package to a fixed version below.
- Debian/vnc4—upgrade to 4.1.1+X4.3.0-10 or later
Is CVE-2006-2369 being exploited?
Likely — EPSS is 91.5%, placing CVE-2006-2369 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 4.1.1+X4.3.0-10