CVE-2006-2369
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
- Affected products
- Adderlink Ip, Cisco Callmanager, Realvnc
- Vnc Realvnc
- = 4.1.1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 91.4% (100th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2006-05-15
CVE-2006-2369 at NVD
14 known exploits for CVE-2006-2369
Proof-of-concept code and exploit modules indexed by Sploitus
Exploit for Improper Authentication in Vnc Realvnc
VNC Authentication None Detection
RealVNC Authentication Bypass
RealVNC 4.1.04.1.1 - Authentication Bypass
RealVNC 4.1.0/4.1.1 - Authentication Bypass
RealVNC NULL Authentication Mode Bypass
RealVNC 4.1 Authentication Bypass
RealVNC Authentication Bypass
RealVNC - Authentication Bypass (Metasploit)
RealVNC Authentication Bypass
VNC Authentication None Detection
RealVNC 4.1.0 < 4.1.1 - VNC Null Authentication Bypass
Immunity Canvas: REALVNC_NOAUTH
RealVNC 4.1.0 < 4.1.1 - VNC Null Authentication Bypass (Metasploit)