← Back

CVE-2013-6765

nvd nist
Published: May 19, 2014Modified: May 6, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

Affected (26)

1 product
Openvas Manager
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Openvas
Version 4.0.0
Version 4.0.1
Version 4.0.2
Version 4.0.3
Version 4.0 beta1
Version 4.0 beta2
Version 4.0 beta3
Version 4.0 beta4
Version 4.0 beta5
Version 4.0 rc1
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Openvas
Version 3.0.0
Version 3.0.1
Version 3.0.2
Version 3.0.3
Version 3.0.4
Version 3.0.5
Version 3.0.6
Version 3.0 beta1
Version 3.0 beta2
Version 3.0 beta3
Version 3.0 beta4
Version 3.0 beta5
Version 3.0 beta6
Version 3.0 beta7
Version 3.0 beta8
Version 3.0 rc1

Timeline

No history available yet.