CVE-2013-1430: Critical severity Neutrinolabs Xrdp vulnerability
Published Dec 16, 2016
·Updated
An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman${username}passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.
Affected Software
4 affected componentsFixes available
Neutrinolabs Xrdp<=0.8.0
Debian Debian Linux=7.0
Debian Debian Linux=8.0
debian/xrdp
0.9.21.1-1~deb11u10.9.21.1-1~deb11u30.9.21.1-1+deb12u10.9.21.1-1+deb12u20.10.1-3.10.10.1-3.1+deb13u10.10.1-4.1
Remediation
Patch Available
Event History
Dec 16, 2016
CVE Published
via MITRE·09:02 AM
Data Sourced
via MITRE·09:02 AM
DescriptionWeakness
Feb 18, 2026
Data Sourced
via Debian·03:30 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-1430?
CVE-2013-1430 has a medium severity rating due to the exposure of user passwords.
2
How do I fix CVE-2013-1430?
To mitigate CVE-2013-1430, upgrade xrdp to version 0.9.1 or later.
3
What kind of attack can exploit CVE-2013-1430?
CVE-2013-1430 can be exploited by an attacker who gains access to the user's file system, retrieving the cleartext password from the created file.
4
Which versions of xrdp are affected by CVE-2013-1430?
CVE-2013-1430 affects xrdp versions prior to 0.9.1.
5
Is CVE-2013-1430 a local or remote vulnerability?
CVE-2013-1430 is primarily a local vulnerability, as it requires access to the user's file system.