CVE Vulnerabilities

CVE-2012-5003

Improper Authentication

Published: Sep 19, 2012 | Modified: Aug 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

nxapplet.jar in No Machine NX Web Companion 3.x and earlier does not properly verify the authenticity of updates, which allows user-assisted remote attackers to execute arbitrary code via a crafted (1) SiteUrl or (2) RedirectUrl parameter that points to a Trojan Horse client.zip update file.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Nx_web_companion Nomachine * 3.5.0-2 (including)
Nx_web_companion Nomachine 1.5.0-beta2 (including) 1.5.0-beta2 (including)
Nx_web_companion Nomachine 1.5.0-beta3 (including) 1.5.0-beta3 (including)
Nx_web_companion Nomachine 2.0.0-1 (including) 2.0.0-1 (including)
Nx_web_companion Nomachine 2.1.0-1 (including) 2.1.0-1 (including)
Nx_web_companion Nomachine 3.0.0-1 (including) 3.0.0-1 (including)
Nx_web_companion Nomachine 3.0.0-2 (including) 3.0.0-2 (including)
Nx_web_companion Nomachine 3.0.0-3 (including) 3.0.0-3 (including)
Nx_web_companion Nomachine 3.0.0-4 (including) 3.0.0-4 (including)
Nx_web_companion Nomachine 3.0.0-5 (including) 3.0.0-5 (including)
Nx_web_companion Nomachine 3.1.0-1 (including) 3.1.0-1 (including)
Nx_web_companion Nomachine 3.2.0-1 (including) 3.2.0-1 (including)
Nx_web_companion Nomachine 3.3.0-1 (including) 3.3.0-1 (including)
Nx_web_companion Nomachine 3.3.0-2 (including) 3.3.0-2 (including)
Nx_web_companion Nomachine 3.4.0-1 (including) 3.4.0-1 (including)
Nx_web_companion Nomachine 3.4.0-2 (including) 3.4.0-2 (including)
Nx_web_companion Nomachine 3.4.0-3 (including) 3.4.0-3 (including)
Nx_web_companion Nomachine 3.5.0-1 (including) 3.5.0-1 (including)

Potential Mitigations

References