[Openvas-announce] 20131108 Security Releases for OpenVAS-5 and OpenVAS-6mailing list
http://lists.wald.intevation.org/pipermail/openvas-announce/2013-November/000157.html CVE-2013-6765
OpenVAS Manager 4.0 - Authentication Bypass
Record summary
CVE-2013-6765 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBOpenVAS Manager 4.0 - Authentication BypassExploitDB exploitby EccENot analyzed1 file
References
4openvas.orgConfirmation
http://www.openvas.org/OVSA20131108.html [oss-security] 20131110 CVE-2013-6765 CVE-2013-6766 for OpenVAS 4.0.4/1.3.2/etc.mailing list
http://www.openwall.com/lists/oss-security/2013/11/10/2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-6765