PoC Index

CVE-2006-2369

HIGH 7.5EPSS 92.4%

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

CVSS v2.0
7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS
92.36% chance of exploitation in the next 30 days, 100th percentile
Published
2006-05-15
Updated
2024-08-07

Proof-of-concept exploits (1)

Metasploit modules (1)

ExploitDB entries (4)

References

Related