7.5
CVSSv3

CVE-2022-24882

Published: 26/04/2022 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions before 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freerdp freerdp

fedoraproject fedora 34

fedoraproject extra packages for enterprise linux 8.0

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

FreeRDP could allow unintended access to network services ...
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP) In versions prior to 270, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value This issue affects FreeRDP based RDP Server implementations RDP clients are not affected The vulnerability is patched in FreeRDP 270 Ther ...
freerdp server with NTLM authentication does not properly abort on empty password ...