10
CVSSv3

CVE-2022-25226

Published: 18/04/2022 Updated: 08/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cybelsoft thinvnc 1.0