OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set to CLIENT_AUTHENTIC.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2014-05-19 07:55
Updated : 2014-05-20 04:37
NVD link : CVE-2013-6766
Mitre link : CVE-2013-6766
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
openvas
- openvas_administrator