CVE Vulnerabilities

CVE-2013-6766

Improper Authentication

Published: May 19, 2014 | Modified: Apr 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set to CLIENT_AUTHENTIC.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Openvas_administratorOpenvas1.2-rc1 (including)1.2-rc1 (including)
Openvas_administratorOpenvas1.2.0 (including)1.2.0 (including)
Openvas_administratorOpenvas1.2.1 (including)1.2.1 (including)
Openvas_administratorOpenvas1.3-beta1 (including)1.3-beta1 (including)
Openvas_administratorOpenvas1.3-rc1 (including)1.3-rc1 (including)
Openvas_administratorOpenvas1.3.0 (including)1.3.0 (including)
Openvas_administratorOpenvas1.3.1 (including)1.3.1 (including)
Openvas-serverUbuntulucid*
Openvas-serverUbuntuprecise*
Openvas-serverUbuntuquantal*
Openvas-serverUbunturaring*
Openvas-serverUbuntusaucy*
Openvas-serverUbuntutrusty*
Openvas-serverUbuntuutopic*

Potential Mitigations

References