Impact
FreeRDP server versions before 3.31.0 contain a protocol negotiation bypass that allows unauthenticated attackers to send incompatible protocol requests, trigger negotiation failures, then complete a TLS handshake and enter RDSTLS mode. This bypasses any server policy that restricts RDSTLS before authentication, effectively granting an attacker the ability to establish an encrypted RDP session without proper authentication. The flaw is classified as CWE-358 and CWE-693.
Affected Systems
Affected vendors include FreeRDP. The product FreeRDP, versions from 3.0.0 up to and including 3.30.0, are vulnerable.
Risk and Exploitability
Based on the description, it is inferred that attackers can exploit this vulnerability remotely over the network by sending specially crafted protocol requests to a vulnerable FreeRDP server. The flaw enables an unauthenticated attacker to complete a TLS handshake and enter RDSTLS mode even when the server policy disables RDSTLS before authentication. The EPSS score indicates a very low but non-zero probability of exploitation, while the CVSS score of 9.2 reflects critical severity. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment