First published: Fri Jul 12 2024(Updated: )
xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
xrdp | <0.10.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-39917 has a high severity level due to its potential for brute force login attacks.
To fix CVE-2024-39917, upgrade xrdp to version 0.10.0 or later.
CVE-2024-39917 affects xrdp versions prior to 0.10.0.
Yes, CVE-2024-39917 can allow attackers to gain unauthorized access through infinite login attempts.
You should check the 'MaxLoginRetry' configuration parameter in '/etc/xrdp/sesman.ini'.