Vulnerabilities > CVE-2012-0681 - Cryptographic Issues vulnerability in Apple Remote Desktop 3.5.2/3.5.3/3.6.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Apple Remote Desktop before 3.6.1 does not recognize the "Encrypt all network data" setting during connections to third-party VNC servers, which allows remote attackers to obtain cleartext VNC session content by sniffing the network.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Common Weakness Enumeration (CWE)
Common Attack Pattern Enumeration and Classification (CAPEC)
- Signature Spoofing by Key Recreation An attacker obtains an authoritative or reputable signer's private signature key by exploiting a cryptographic weakness in the signature algorithm or pseudorandom number generation and then uses this key to forge signatures from the original signer to mislead a victim into performing actions that benefit the attacker.
Nessus
NASL family | MacOS X Local Security Checks |
NASL id | MACOSX_REMOTE_DESKTOP_3_6_1.NASL |
description | According to its version, the Admin component in the Apple Remote Desktop install on the remote host reportedly fails to encrypt data and does not issue a warning when connecting to a third-party VNC server with |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 61621 |
published | 2012-08-22 |
reporter | This script is Copyright (C) 2012-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/61621 |
title | Apple Remote Desktop < 3.5.3 / 3.6.1 Information Disclosure (Mac OS X) |
code |
|
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 55100 CVE ID: CVE-2012-0681 Apple Remote Desktop 是管理你网络上的Mac 电脑的最佳方式。 Apple Remote Desktop 3.5.2-3.6中,连接到第三方VNC服务器并设置了“Encrypt all network data”时,数据在未加密的方式下传送,而没有警告,远程攻击者可利用此漏洞获取敏感信息。 0 Apple Remote Desktop 3.x 厂商补丁: Apple ----- Apple已经为此发布了一个安全公告(HT5433)以及相应补丁: HT5433:About the security content of Apple Remote Desktop 3.6.1 链接:http://support.apple.com/kb/HT5433 |
id | SSV:60342 |
last seen | 2017-11-19 |
modified | 2012-08-23 |
published | 2012-08-23 |
reporter | Root |
title | Apple Remote Desktop信息泄露漏洞 |