Vulnerability in Neat VNC Server Could Allow for Security Type Tampering
CVE-2024-42458

9.8CRITICAL

Key Information:

Vendor

Neat VNC

Status
Vendor
CVE Published:
2 August 2024

What is CVE-2024-42458?

The vulnerability stems from the improper validation of the security type in the Neat VNC server component. This issue allows potential unauthorized access or manipulation of the VNC sessions, posing a security risk to users of Neat VNC versions prior to 0.8.1. It is associated with a historical issue, CVE-2006-2369, indicating that similar vulnerabilities have existed in the past. Addressing this flaw is critical for ensuring the integrity and confidentiality of remote desktop sessions.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.