CVE-2021-44425
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).
Se ha detectado un problema en AnyDesk versiones anteriores a 6.2.6 y en versiones 6.3.x anteriores a 6.3.3. Un puerto de escucha innecesariamente abierto en una máquina en la LAN de un atacante, abierto por el cliente de Windows de AnyDesk cuando es usada la funcionalidad tunneling, permite al atacante acceder sin autorización a la pila de protocolos de tunelización de AnyDesk de la máquina local (y también a cualquier software de la máquina de destino remota que esté escuchando el puerto tunelizado de AnyDesk)
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-29 CVE Reserved
- 2022-09-12 CVE Published
- 2024-04-04 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://anydesk.com/en/downloads/windows | 2022-09-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Anydesk Search vendor "Anydesk" | Anydesk Search vendor "Anydesk" for product "Anydesk" | < 6.2.6 Search vendor "Anydesk" for product "Anydesk" and version " < 6.2.6" | windows |
Affected
| ||||||
Anydesk Search vendor "Anydesk" | Anydesk Search vendor "Anydesk" for product "Anydesk" | >= 6.3.0 < 6.3.3 Search vendor "Anydesk" for product "Anydesk" and version " >= 6.3.0 < 6.3.3" | windows |
Affected
|