CVE-2013-6765
OpenVAS Manager 3.0-3.0.6 and 4.0-4.0.3 - Unauthenticated OMP Command Execution via Version Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6765. PoCs published by EccE.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass vulnerability in OpenVAS Manager 4.0 by sending unauthenticated OMP protocol commands over SSL. It retrieves version and slave information without valid credentials.
Description
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.
Exploits (1)
This exploit demonstrates an authentication bypass vulnerability in OpenVAS Manager 4.0 by sending unauthenticated OMP protocol commands over SSL. It retrieves version and slave information without valid credentials.