7.5
CVSSv2

CVE-2002-1336

Published: 11/12/2002 Updated: 10/10/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

TightVNC prior to 1.2.6 generates the same challenge string for multiple connections, which allows remote malicious users to bypass VNC authentication by sniffing the challenge and response of other users.

Vulnerable Product Search on Vulmon Subscribe to Product

tightvnc tightvnc 1.2.4

tightvnc tightvnc 1.2.5

tightvnc tightvnc 1.2.1

tightvnc tightvnc 1.2.3

tightvnc tightvnc 1.2.0