Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

OpenVAS Administrator Authentication Bypass

Information

Severity

Severity

High

Family

Family

General

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

10 years ago

Modified

Modified

5 years ago

Summary

The remote OpenVAS Administrator is prone to an authentication bypass.

Insight

Insight

A software bug in the server module 'OpenVAS Administrator' allowed to bypass the OAP authentication procedure. The attack vector is remotely available in case public OAP is enabled. In case of successful attack, the attacker gains partial rights to execute OAP commands.

Detection Method

Detection Method

Try to bypass OAP authentication by sending a special crafted request.

Solution

Solution

Update to version 1.2.2 or 1.3.2.

Common Vulnerabilities and Exposures (CVE)