Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
FreeRDP Server authentication might allow invalid credentials to pass
Vulnerability Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
FreeRDP授权问题漏洞
Vulnerability Description
FreeRDP是Freerdp团队的一款开源的远程桌面协议(RDP)的实现。 FreeRDP存在授权问题漏洞,该漏洞源于在 2.7.0 版之前,如果服务器配置了无效的 SAM 文件路径,则针对无效凭据的服务器端身份验证可能会成功。
CVSS Information
N/A
Vulnerability Type
N/A