Security Advisory

CVE-2013-6765

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2014-05-19 14:00:00
Last updated 2024-08-06 17:46:23
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.