CVE Vulnerabilities

CVE-2013-6765

Improper Authentication

Published: May 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Openvas_managerOpenvas4.0-beta1 (including)4.0-beta1 (including)
Openvas_managerOpenvas4.0-beta2 (including)4.0-beta2 (including)
Openvas_managerOpenvas4.0-beta3 (including)4.0-beta3 (including)
Openvas_managerOpenvas4.0-beta4 (including)4.0-beta4 (including)
Openvas_managerOpenvas4.0-beta5 (including)4.0-beta5 (including)
Openvas_managerOpenvas4.0-rc1 (including)4.0-rc1 (including)
Openvas_managerOpenvas4.0.0 (including)4.0.0 (including)
Openvas_managerOpenvas4.0.1 (including)4.0.1 (including)
Openvas_managerOpenvas4.0.2 (including)4.0.2 (including)
Openvas_managerOpenvas4.0.3 (including)4.0.3 (including)
Openvas-serverUbuntulucid*
Openvas-serverUbuntuprecise*
Openvas-serverUbuntuquantal*
Openvas-serverUbunturaring*
Openvas-serverUbuntusaucy*
Openvas-serverUbuntutrusty*
Openvas-serverUbuntuutopic*

Potential Mitigations

References