CVE-2006-2369
EPSS 91.5%
描述
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
如何修補 CVE-2006-2369
要修補 CVE-2006-2369,請將受影響套件升級到下列已修補版本。
- Debian/vnc4—升級至 4.1.1+X4.3.0-10 或更新版本
CVE-2006-2369 正在被利用嗎?
可能 — EPSS 為 91.5%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- from 0, < 4.1.1+X4.3.0-10