Back

CRITICAL

libvirt: Setting empty VNC password allows access to unauthorized users

Published Jul 13, 2016

Description

libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 13, 2016
Updated Aug 6, 2024
Reserved May 24, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jan 18, 2015