20020703 SunPCi II VNC weak authentication scheme vulnerabilitymailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q3/0003.html CVE-2002-0994
Sun SunPCi II VNC Software 2.3 - Password Disclosure
Record summary
CVE-2002-0994 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing the random byte challenge, which is used as the key for encrypted communications.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSun SunPCi II VNC Software 2.3 - Password DisclosureExploitDB exploitby Richard van den BergNot analyzed1 file
References
4sunpci-vnc-weak-authentication(9476)vdb entry
http://www.iss.net/security_center/static/9476.php 5146vdb entry
http://www.securityfocus.com/bid/5146 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-0994