WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Winvnc | Att | * | 3.3.3 (including) |