WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Winvnc | Att | * | 3.3.3 (including) |