TeamViewer Linux - Deletion command not properly executed after process crash
CVE-2022-23242

6.3MEDIUM

Key Information:

Vendor

Teamviewer

Vendor
CVE Published:
22 March 2022

What is CVE-2022-23242?

TeamViewer Linux versions before 15.28 do not properly execute a deletion command for the connection password in case of a process crash. Knowledge of the crash event and the TeamViewer ID as well as either possession of the pre-crash connection password or local authenticated access to the machine would have allowed to establish a remote connection by reusing the not properly deleted connection password.

Affected Version(s)

TeamViewer for Linux Linux 15.27

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.