Lucene search

K
osvGoogleOSV:USN-5461-1
HistoryJun 06, 2022 - 4:33 p.m.

freerdp2 vulnerabilities

2022-06-0616:33:28
Google
osv.dev
15
freerdp
vulnerabilities
ubuntu
server authentication
cve-2022-24882
cve-2022-24883

AI Score

7.4

Confidence

Low

EPSS

0.005

Percentile

75.5%

It was discovered that FreeRDP incorrectly handled empty password values. A
remote attacker could use this issue to bypass server authentication. This
issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 21.10.
(CVE-2022-24882)

It was discovered that FreeRDP incorrectly handled server configurations
with an invalid SAM file path. A remote attacker could use this issue to
bypass server authentication. (CVE-2022-24883)