CVE-2012-0681: Medium severity apple remote desktop vulnerability
Published Aug 22, 2012
·Updated
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
Affected Software
3 affected components
Apple Apple Remote Desktop=3.5.2
Apple Apple Remote Desktop=3.5.3
Apple Apple Remote Desktop=3.6.0
Event History
Aug 22, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0681?
CVE-2012-0681 is considered a moderate severity vulnerability due to its potential to expose sensitive VNC session content.
2
How do I fix CVE-2012-0681?
To fix CVE-2012-0681, upgrade Apple Remote Desktop to version 3.6.1 or later.
3
What type of attack is possible with CVE-2012-0681?
CVE-2012-0681 allows remote attackers to intercept cleartext VNC session content through network sniffing.
4
Which versions of Apple Remote Desktop are affected by CVE-2012-0681?
Versions 3.5.2, 3.5.3, and 3.6.0 of Apple Remote Desktop are affected by CVE-2012-0681.
5
Does CVE-2012-0681 affect connections to Apple VNC servers?
No, CVE-2012-0681 specifically affects connections to third-party VNC servers.