CVE-2006-2206: Weak Encryption
Published May 5, 2006
·Updated
The MS-Logon authentication scheme in UltraVNC (aka Ultr@VNC) 1.0.1 uses weak encryption (XOR) for challenge/response, which allows remote attackers to gain privileges by sniffing and decrypting passwords.
Affected Software
1 affected component
UltraVNC UltraVNC=1.0.1
Event History
May 5, 2006
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2206?
CVE-2006-2206 is considered to have a high severity due to the use of weak encryption in the MS-Logon authentication scheme.
2
How do I fix CVE-2006-2206?
To fix CVE-2006-2206, users should upgrade to a newer version of UltraVNC that does not utilize weak encryption.
3
What types of attacks can exploit CVE-2006-2206?
CVE-2006-2206 can be exploited by remote attackers who can sniff network traffic to decrypt user passwords.
4
What software is affected by CVE-2006-2206?
CVE-2006-2206 specifically affects UltraVNC version 1.0.1.
5
How does CVE-2006-2206 impact user security?
CVE-2006-2206 impacts user security by allowing unauthorized privilege escalation through compromised passwords.