ZeroHour

CVE-2022-25226

PoC
CVSS 3.1
10.0 critical
EPSS
11%p96
Published
()
Modified
Description

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

Vendors
cybelsoft
Products
thinvnc
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.