CVE-2013-6765

Openvas Manager - Authentication Bypass

Title source: rule

Description

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Exploits (1)

exploitdb WORKING POC
by EccE · pythonremotelinux
https://www.exploit-db.com/exploits/34026

Scores

EPSS 0.0454
EPSS Percentile 89.0%

Classification

CWE
CWE-287
Status draft

Affected Products (26)

openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
openvas/openvas_manager
... and 11 more

Timeline

Published May 19, 2014
Tracked Since Feb 18, 2026