Impact
FreeRDP’s RDSTLS server fails to enforce the proper sequence of protocol messages. A remote client can send a Capability PDU at the wrong stage, causing the server to accept the exchange as successful and skip credential checks, thereby granting unauthenticated access to the RDP session.
Affected Systems
The flaw affects the FreeRDP project, specifically all versions released before 3.30.0. Any deployment running those versions is vulnerable.
Risk and Exploitability
The CVSS score of 8.3 categorizes the vulnerability as high severity. EPSS indicates a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote, network‑based, and requires no pre‑existing authentication credentials. An attacker could contact the RDSTLS endpoint over the network and trigger the bypass to establish a session without authenticating.
OpenCVE Enrichment