Vulnerabilities
Vulnerable Software
Tigervnc:  >> Tigervnc  >> 1.1  Security Vulnerabilities
The CSecurityTLS::processMsg function in common/rfb/CSecurityTLS.cxx in the vncviewer component in TigerVNC 1.1beta1 does not properly verify the server's X.509 certificate, which allows man-in-the-middle attackers to spoof a TLS VNC server via an arbitrary certificate.
CVSS Score
5.8
EPSS Score
0.006
Published
2011-05-26


Contact Us

Shodan ® - All rights reserved