Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
FreeRDP: RDSTLS server authentication bypass: a credential-less Capabilities PDU is accepted at the auth step (fail-open `resultCode`)
Vulnerability Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an attacker-supplied RDSTLS_TYPE_CAPABILITIES PDU while rdstls_server_authenticate is waiting for RDSTLS_TYPE_AUTHREQ, leaving resultCode at RDSTLS_RESULT_SUCCESS and allowing a remote unauthenticated client to bypass the RedirectionGuid, username, domain, or password checks. This issue is fixed in version 3.30.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
认证机制不恰当
Vulnerability Title
FreeRDP 授权问题漏洞
Vulnerability Description
FreeRDP是FreeRDP组织开源的一款远程桌面协议(RDP)的实现。 FreeRDP 3.30.0之前版本存在授权问题漏洞,该漏洞源于libfreerdp/core/rdstls.c中的服务器端RDSTLS在等待RDSTLS_TYPE_AUTHREQ时接受攻击者提供的RDSTLS_TYPE_CAPABILITIES PDU,使resultCode保持为RDSTLS_RESULT_SUCCESS,导致远程未认证客户端绕过RedirectionGuid、用户名、域名或密码检查。
CVSS Information
N/A
Vulnerability Type
N/A