7.5

CVE-2013-6765

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Data is provided by the National Vulnerability Database (NVD)
OpenvasOpenvas Manager Version4.0 Updatebeta1
OpenvasOpenvas Manager Version4.0 Updatebeta2
OpenvasOpenvas Manager Version4.0 Updatebeta3
OpenvasOpenvas Manager Version4.0 Updatebeta4
OpenvasOpenvas Manager Version4.0 Updatebeta5
OpenvasOpenvas Manager Version4.0 Updaterc1
OpenvasOpenvas Manager Version4.0.0
OpenvasOpenvas Manager Version4.0.1
OpenvasOpenvas Manager Version4.0.2
OpenvasOpenvas Manager Version4.0.3
OpenvasOpenvas Manager Version3.0 Updatebeta1
OpenvasOpenvas Manager Version3.0 Updatebeta2
OpenvasOpenvas Manager Version3.0 Updatebeta3
OpenvasOpenvas Manager Version3.0 Updatebeta4
OpenvasOpenvas Manager Version3.0 Updatebeta5
OpenvasOpenvas Manager Version3.0 Updatebeta6
OpenvasOpenvas Manager Version3.0 Updatebeta7
OpenvasOpenvas Manager Version3.0 Updatebeta8
OpenvasOpenvas Manager Version3.0 Updaterc1
OpenvasOpenvas Manager Version3.0.0
OpenvasOpenvas Manager Version3.0.1
OpenvasOpenvas Manager Version3.0.2
OpenvasOpenvas Manager Version3.0.3
OpenvasOpenvas Manager Version3.0.4
OpenvasOpenvas Manager Version3.0.5
OpenvasOpenvas Manager Version3.0.6
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 4.88% 0.885
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.