4.3
CVSSv2

CVE-2011-0011

Published: 21/06/2012 Updated: 02/11/2020
CVSS v2 Base Score: 4.3 | Impact Score: 6.4 | Exploitability Score: 3.2
VMScore: 383
Vector: AV:A/AC:H/Au:N/C:P/I:P/A:P

Vulnerability Summary

qemu-kvm prior to 0.11.0 disables VNC authentication when the password is cleared, which allows remote malicious users to bypass authentication and establish VNC sessions.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu

qemu qemu 0.11.0

qemu qemu 0.10.1

qemu qemu 0.10.0

qemu qemu 0.1.0

qemu qemu 0.10.3

qemu qemu 0.10.2

qemu qemu 0.1.2

qemu qemu 0.1.1

qemu qemu 0.10.6

qemu qemu 0.1.6

qemu qemu 0.1.5

qemu qemu 0.10.5

qemu qemu 0.10.4

qemu qemu 0.1.4

qemu qemu 0.1.3

Vendor Advisories

Blank passwords allowed unrestricted QEMU VNC session access ...