PT-2026-23456 · Unknown · Rustdesk Server+1
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk Server Pro versions through 1.7.5
RustDesk Server (OSS) versions through 1.1.15
Description
The software contains a flaw related to insufficient restriction of excessive authentication attempts and the use of a password hash with insufficient computational effort, potentially allowing password brute forcing. The issue impacts the peer authentication and API login modules. The vulnerability is linked to code within the
src/server/connection.Rs file, specifically concerning salt and challenge generation, and the SHA256(SHA256(pwd+salt)+challenge) verification process.Recommendations
Update RustDesk Server Pro to a version later than 1.7.5.
Update RustDesk Server (OSS) to a version later than 1.1.15.
Exploit
Fix
Improper Restriction of Excessive Authentication Attempts
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rustdesk Server
Rustdesk Server Pro