xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
Metrics
Affected Vendors & Products
References
History
Thu, 05 Sep 2024 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Neutrinolabs
Neutrinolabs xrdp |
|
CPEs | cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:* | |
Vendors & Products |
Neutrinolabs
Neutrinolabs xrdp |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-07-12T15:24:01.307Z
Updated: 2024-08-02T04:33:11.745Z
Reserved: 2024-07-02T19:37:18.602Z
Link: CVE-2024-39917
Vulnrichment
Updated: 2024-08-02T04:33:11.745Z
NVD
Status : Modified
Published: 2024-07-12T16:15:04.620
Modified: 2024-11-21T09:28:33.763
Link: CVE-2024-39917
Redhat
No data.