PT-2022-23368 · Osu Open Source · Vncauthproxy

Mlevogiannis

·

Published

2022-09-14

·

Updated

2024-08-01

·

CVE-2022-36436

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OSU Open Source Lab VNCAuthProxy versions 1.1.1 and earlier
Description The issue is an authentication-bypass vulnerability in the VNCServerAuthenticator, located in vncap/vnc/protocol.py, which could allow a malicious actor to gain unauthorized access to a VNC session or to disconnect a legitimate user from a VNC session. A remote attacker with network access to the proxy server could leverage this vulnerability to connect to VNC servers protected by the proxy server without providing any authentication credentials. Exploitation of this issue requires that the proxy server is currently accepting connections for the target VNC server.
Recommendations For OSU Open Source Lab VNCAuthProxy versions 1.1.1 and earlier, consider disabling the VNCServerAuthenticator function until a patch is available to prevent unauthorized access to VNC sessions. Restrict access to the proxy server to minimize the risk of exploitation. Avoid using the proxy server to connect to VNC servers until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2022-36436
GHSA-237R-MX84-7X8C
PYSEC-2022-267

Affected Products

Vncauthproxy