CVE-2013-6765: High severity OpenVAS OpenVAS Manager vulnerability
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENTAUTHENTIC, as demonstrated by the ompxmlhandleendelement function in omp.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6765?
The severity of CVE-2013-6765 is considered medium, as it allows remote attackers to bypass authentication restrictions.
How do I fix CVE-2013-6765?
To fix CVE-2013-6765, upgrade OpenVAS Manager to version 3.0.7 or 4.0.4 or later.
What versions of OpenVAS Manager are affected by CVE-2013-6765?
CVE-2013-6765 affects OpenVAS Manager versions prior to 3.0.7 and 4.0.4.
What kind of attacks can CVE-2013-6765 facilitate?
CVE-2013-6765 can facilitate unauthorized execution of OMP commands by bypassing authentication.
Is there a known exploit for CVE-2013-6765?
Yes, there are demonstrations of CVE-2013-6765 that show how to exploit the vulnerability through crafted OMP requests.