7.5
CVSSv2

CVE-2013-6765

Published: 19/05/2014 Updated: 19/05/2014
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

OpenVAS Manager 3.0 prior to 3.0.7 and 4.0 prior to 4.0.4 allows remote malicious users to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Vulnerable Product Search on Vulmon Subscribe to Product

openvas openvas manager 4.0

openvas openvas manager 4.0.0

openvas openvas manager 4.0.1

openvas openvas manager 4.0.2

openvas openvas manager 4.0.3

openvas openvas manager 3.0

openvas openvas manager 3.0.0

openvas openvas manager 3.0.1

openvas openvas manager 3.0.2

openvas openvas manager 3.0.3

openvas openvas manager 3.0.5

openvas openvas manager 3.0.6

openvas openvas manager 3.0.4

Exploits

#!/usr/bin/python # Exploit Title: OpenVAS Manager 40 Authentication Bypass Vulnerability PoC # Date: 09/07/2014 # Exploit Author: EccE # Vendor Homepage: wwwopenvasorg/ # Software Link: waldintevationorg/frs/?group_id=29 # Version: OpenVAS Manager 40 # Tested on: Debian GNU/Linux testing (jessie) # CVE : CVE-2013-6765 """ ...