Logo
vulnerabilityCVE-2022-24882
Name
CVE-2022-24882
Source
NVD ( link)Debian ( link)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There are currently no known workarounds.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Exploitable

Vulnerability Ratings#


9.1
CVSSv31
7.5
CVSSv31
5
CVSSv2
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Not Affected
buildroot
master
2.11.8
Not Affected
yocto
master
2.11.8
Not Affected
yocto
master
3.26.0
Not Affected
yocto
scarthgap
2.11.8
Not Affected
yocto
scarthgap
3.4.0
Not Affected