Vulnerability Details CVE-2012-0681
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 64.7%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2012-0681
-
cpe:2.3:a:apple:apple_remote_desktop:3.5.2
-
cpe:2.3:a:apple:apple_remote_desktop:3.5.3
-
cpe:2.3:a:apple:apple_remote_desktop:3.6.0