VDB

CVE-2017-2488

CVE-2017-2488 PUBLISHED CVSS 7.5 HIGH

A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.

EPSS 0.59% · 45.1th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.59%
45.1th percentile

Affected Products

VendorProductVersions
AppleApple Remote Desktopunspecified
appleremote_desktop0

Timeline

  • Dec 23, 2021 CVE Published
  • Dec 24, 2021 EPSS Score
  • Jan 8, 2022 CVE Updated
  • Feb 4, 2022 EPSS Score
  • Feb 16, 2022 EPSS Score
  • Apr 11, 2022 EPSS Score
  • Jun 4, 2022 EPSS Score
  • Jul 29, 2022 EPSS Score
  • Sep 22, 2022 EPSS Score
  • Nov 15, 2022 EPSS Score
  • Mar 3, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›