vendor:
OpenVAS Manager
by:
EccE
8,8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: OpenVAS Manager
Affected Version From: OpenVAS Manager 4.0
Affected Version To: OpenVAS Manager 4.0
Patch Exists: YES
Related CWE: CVE-2013-6765
CPE: a:openvas:openvas_manager:4.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Debian GNU/Linux testing (jessie)
2014
OpenVAS Manager 4.0 Authentication Bypass Vulnerability PoC
OpenVAS Manager 4.0 is vulnerable to an authentication bypass vulnerability. An attacker can exploit this vulnerability to gain access to the OpenVAS Manager without authentication. This vulnerability is due to the lack of authentication checks for certain commands. An attacker can send a specially crafted request to the OpenVAS Manager to bypass authentication and gain access to the system.
Mitigation:
Upgrade to OpenVAS Manager 4.0.1 or later versions.