Security Advisory

CVE-2022-25226

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2022-04-18 16:20:44
Last updated 2024-08-03 04:36:06
Assigner Fluid Attacks
CVSS score not scored
State PUBLISHED

Description

ThinVNC version 1.0b1 allows an unauthenticated user to bypass the authentication process via 'http://thin-vnc:8080/cmd?cmd=connect' by obtaining a valid SID without any kind of authentication. It is possible to achieve code execution on the server by sending keyboard or mouse events to the server.