VYPR
Critical severity9.8NVD Advisory· Published Dec 16, 2016· Updated May 6, 2026

CVE-2013-1430

CVE-2013-1430

Description

An issue was discovered in xrdp before 0.9.1. When successfully logging in using RDP into an xrdp session, the file ~/.vnc/sesman_${username}_passwd is created. Its content is the equivalent of the user's cleartext password, DES encrypted with a known key.

Affected products

4
  • Range: xrdp before 0.9.1
  • cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*
    Range: <=0.8.0
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    • cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.