CVE-2022-24883
FreeRDP Server authentication might allow invalid credentials to pass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against a `SAM` file are affected. Version 2.7.0 contains a fix for this issue. As a workaround, use custom authentication via `HashCallback` and/or ensure the `SAM` database path configured is valid and the application has file handles left.
FreeRDP es una implementación libre del protocolo de escritorio remoto (RDP). En versiones anteriores a 2.7.0, la autenticación del lado del servidor contra un archivo "SAM" podría tener éxito para credenciales inválidas si el servidor ha configurado una ruta de archivo "SAM" inválida. Los clientes basados en FreeRDP no están afectados. Las implementaciones de servidores RDP que usan FreeRDP para autenticar contra un archivo "SAM" están afectadas. La versión 2.7.0 contiene una corrección para este problema. Como mitigación, use la autenticación personalizada por medio de "HashCallback" y/o asegúrese de que la ruta de la base de datos "SAM" configurada es válida y que la aplicación dispone de los manejadores del archivo
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-02-10 CVE Reserved
- 2022-04-26 CVE Published
- 2024-08-03 CVE Updated
- 2024-11-04 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-287: Improper Authentication
CAPEC
References (9)
URL | Tag | Source |
---|---|---|
https://github.com/FreeRDP/FreeRDP/releases/tag/2.7.0 | Release Notes | |
https://lists.debian.org/debian-lts-announce/2023/11/msg00010.html | Mailing List |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Freerdp Search vendor "Freerdp" | Freerdp Search vendor "Freerdp" for product "Freerdp" | < 2.7.0 Search vendor "Freerdp" for product "Freerdp" and version " < 2.7.0" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 34 Search vendor "Fedoraproject" for product "Fedora" and version "34" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 35 Search vendor "Fedoraproject" for product "Fedora" and version "35" | - |
Affected
| ||||||
Fedoraproject Search vendor "Fedoraproject" | Fedora Search vendor "Fedoraproject" for product "Fedora" | 36 Search vendor "Fedoraproject" for product "Fedora" and version "36" | - |
Affected
|