Impact
The flaw lies in the Qt VNC Server’s password authentication logic, allowing an attacker who crafts a VNC client that breaks the RFB protocol to bypass authentication and connect to the server. If successful, the attacker can see, interact with, and potentially modify the shared application, breaching confidentiality and integrity.
Affected Systems
Qt solutions that embed the Qt VNC Server module are affected; the vendor lists only the general Qt product, with no specific component or version details disclosed.
Risk and Exploitability
The CVSS base score of 4.5 indicates moderate severity. No EPSS data is available, and the vulnerability is not catalogued in KEV, yet it remains exploitable because an attacker only needs a VNC client capable of deviating from standard protocol. The workaround requires disabling or patching the VNC Server; otherwise risk of unauthorized remote session remains.
OpenCVE Enrichment