vendor:
ThinVNC
by:
Nikhith Tumamlapalli, WarMarX
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: ThinVNC
Affected Version From: 1.0b1
Affected Version To: 1.0b1
Patch Exists: YES
Related CWE: CVE-2019-17662
CPE: a:thinvnc:thinvnc:1.0b1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows All Platforms
2019
ThinVNC 1.0b1 – Authentication Bypass
Authentication Bypass via Arbitrary File Read. An attacker can exploit this vulnerability by sending a crafted request to the vulnerable server. This will allow the attacker to read arbitrary files from the server.
Mitigation:
Upgrade to the latest version of ThinVNC.