VDB
CVE-2017-2488
CVE-2017-2488
PUBLISHED
CVSS 7.5 HIGH
A cryptographic weakness existed in the authentication protocol of Remote Desktop. This issue was addressed by implementing the Secure Remote Password authentication protocol. This issue is fixed in Apple Remote Desktop 3.9. An attacker may be able to capture cleartext passwords.
EPSS 0.59% · 45.1th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.59%
45.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apple | Apple Remote Desktop | unspecified |
| apple | remote_desktop | 0 |
Timeline
- Dec 23, 2021 CVE Published
- Dec 24, 2021 EPSS Score
- Jan 8, 2022 CVE Updated
- Feb 4, 2022 EPSS Score
- Feb 16, 2022 EPSS Score
- Apr 11, 2022 EPSS Score
- Jun 4, 2022 EPSS Score
- Jul 29, 2022 EPSS Score
- Sep 22, 2022 EPSS Score
- Nov 15, 2022 EPSS Score
- Mar 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score