vendor:
SunPCi II Card
by:
SecurityFocus
7.5
CVSS
HIGH
Weak Authentication Scheme
287
CWE
Product Name: SunPCi II Card
Affected Version From: 2.3
Affected Version To: 2.3
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Solaris
2002
SunPCi VNC Password Decoder
A weakness in the authentication scheme used by the VNC client and server may result in the disclosure of user passwords. An attacker able to sniff unencrypted network traffic during the VNC authentication process may trivially recover the plaintext password.
Mitigation:
Encrypt network traffic with an additional secure layer, such as SSL.