Show plain JSON{"cve": {"data_type": "CVE", "references": {"reference_data": [{"url": "http://www.intelliadmin.com/blog/2006/05/security-flaw-in-realvnc-411.html", "name": "http://www.intelliadmin.com/blog/2006/05/security-flaw-in-realvnc-411.html", "tags": [], "refsource": "MISC"}, {"url": "http://www.intelliadmin.com/blog/2006/05/vnc-flaw-proof-of-concept.html", "name": "http://www.intelliadmin.com/blog/2006/05/vnc-flaw-proof-of-concept.html", "tags": ["Exploit", "Patch"], "refsource": "MISC"}, {"url": "http://www.realvnc.com/products/free/4.1/release-notes.html", "name": "http://www.realvnc.com/products/free/4.1/release-notes.html", "tags": ["Patch"], "refsource": "CONFIRM"}, {"url": "http://www.kb.cert.org/vuls/id/117929", "name": "VU#117929", "tags": ["Patch", "Third Party Advisory", "US Government Resource"], "refsource": "CERT-VN"}, {"url": "http://www.securityfocus.com/bid/17978", "name": "17978", "tags": ["Exploit", "Patch"], "refsource": "BID"}, {"url": "http://securitytracker.com/id?1016083", "name": "1016083", "tags": ["Exploit", "Patch"], "refsource": "SECTRACK"}, {"url": "http://secunia.com/advisories/20107", "name": "20107", "tags": ["Patch", "Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://secunia.com/advisories/20109", "name": "20109", "tags": ["Patch", "Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.osvdb.org/25479", "name": "25479", "tags": [], "refsource": "OSVDB"}, {"url": "http://www.cisco.com/warp/public/707/cisco-sr-20060622-cmm.shtml", "name": "20060622 RealVNC Remote Authentication Bypass Vulnerability", "tags": [], "refsource": "CISCO"}, {"url": "http://secunia.com/advisories/20789", "name": "20789", "tags": ["Vendor Advisory"], "refsource": "SECUNIA"}, {"url": "http://www.vupen.com/english/advisories/2006/1790", "name": "ADV-2006-1790", "tags": ["Vendor Advisory"], "refsource": "VUPEN"}, {"url": "http://www.vupen.com/english/advisories/2006/2492", "name": "ADV-2006-2492", "tags": ["Vendor Advisory"], "refsource": "VUPEN"}, {"url": "http://www.vupen.com/english/advisories/2006/1821", "name": "ADV-2006-1821", "tags": ["Vendor Advisory"], "refsource": "VUPEN"}, {"url": "http://securityreason.com/securityalert/8355", "name": "8355", "tags": [], "refsource": "SREASON"}, {"url": "http://marc.info/?l=vnc-list&m=114755444130188&w=2", "name": "[vnc-list] 20060513 Version 4.1.2", "tags": [], "refsource": "MLIST"}, {"url": "http://marc.info/?l=full-disclosure&m=114768344111131&w=2", "name": "20060515 RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "FULLDISC"}, {"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/26445", "name": "realvnc-auth-bypass(26445)", "tags": [], "refsource": "XF"}, {"url": "http://www.securityfocus.com/archive/1/438368/100/0/threaded", "name": "20060624 Re: Linux VNC evil client patch - BID 17978", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/438175/100/0/threaded", "name": "20060623 Linux VNC evil client patch - BID 17978", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/434560/100/0/threaded", "name": "20060520 Re: [Full-disclosure] RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/434518/100/0/threaded", "name": "20060518 RE: [Full-disclosure] RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/434117/100/0/threaded", "name": "20060516 re: RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/434015/100/0/threaded", "name": "20060515 Re: [Full-disclosure] RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://www.securityfocus.com/archive/1/433994/100/0/threaded", "name": "20060515 RealVNC 4.1.1 Remote Compromise", "tags": [], "refsource": "BUGTRAQ"}, {"url": "http://seclists.org/fulldisclosure/2022/May/29", "name": "20220513 some details regarding CVE-2022-24422 / iDRAC VNC authentication", "tags": [], "refsource": "FULLDISC"}]}, "data_format": "MITRE", "description": {"description_data": [{"lang": "en", "value": "RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as \"Type 1 - None\", which is accepted even if it is not offered by the server, as originally demonstrated using a long password."}]}, "problemtype": {"problemtype_data": [{"description": [{"lang": "en", "value": "CWE-287"}]}]}, "data_version": "4.0", "CVE_data_meta": {"ID": "CVE-2006-2369", "ASSIGNER": "secalert@redhat.com"}}, "impact": {"baseMetricV2": {"cvssV2": {"version": "2.0", "baseScore": 7.5, "accessVector": "NETWORK", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P", "authentication": "NONE", "integrityImpact": "PARTIAL", "accessComplexity": "LOW", "availabilityImpact": "PARTIAL", "confidentialityImpact": "PARTIAL"}, "severity": "HIGH", "impactScore": 6.4, "obtainAllPrivilege": false, "exploitabilityScore": 10.0, "obtainUserPrivilege": false, "obtainOtherPrivilege": true, "userInteractionRequired": false}}, "publishedDate": "2006-05-15T16:06Z", "configurations": {"nodes": [{"children": [], "operator": "OR", "cpe_match": [{"cpe23Uri": "cpe:2.3:a:vnc:realvnc:4.1.1:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true}]}], "CVE_data_version": "4.0"}, "lastModifiedDate": "2022-05-13T18:15Z"}