CVE-2006-2369
HIGH 7.5EPSS 92.4%
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 92.36% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2006-05-15
- Updated
- 2024-08-07
Proof-of-concept exploits (1)
Metasploit modules (1)
ExploitDB entries (4)
- https://www.exploit-db.com/exploits/36932
- https://www.exploit-db.com/exploits/17719
- https://www.exploit-db.com/exploits/1794
- https://www.exploit-db.com/exploits/1791