Record summary

CVE-2013-6765 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.

Description

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBOpenVAS Manager 4.0 - Authentication BypassExploitDB exploitby EccENot analyzed1 file
ExploitDB

PoC details

References

4