CVE-2013-5136: Infoleak
Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-5136?
CVE-2013-5136 has a moderate severity level as it allows potential attackers to sniff sensitive information from unencrypted connections.
How do I fix CVE-2013-5136?
To fix CVE-2013-5136, update Apple Remote Desktop to version 3.7 or later.
What versions of Apple Remote Desktop are affected by CVE-2013-5136?
CVE-2013-5136 affects Apple Remote Desktop versions prior to 3.7, including versions from 3.0.0 up to 3.6.1.
Can CVE-2013-5136 lead to data breaches?
Yes, CVE-2013-5136 can potentially expose sensitive information to attackers, leading to data breaches.
Is there a workaround for CVE-2013-5136?
There are no specific workarounds for CVE-2013-5136, so it is recommended to update the software as the best mitigation strategy.