cbcvebase.
CVE-2016-5008
published 2016-07-13

CVE-2016-5008: libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass…

PriorityP261critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
3.62%
88.2th percentile
libvirt before 2.0.0 improperly disables password checking when the password on a VNC server is set to an empty string, which allows remote attackers to bypass authentication and establish a VNC session by connecting to the server.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlibvirt< libvirt 2.0.0-1 (bookworm)libvirt 2.0.0-1 (bookworm)
redhatlibvirt<= 1.3.5
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 2.0.0-12.0.0-1
redhatlibvirt>= 0 < 1.2.2-0ubuntu13.1.261.2.2-0ubuntu13.1.26
redhatlibvirt>= 0 < 1.3.1-1ubuntu10.191.3.1-1ubuntu10.19

Detection & IOCsextracted from sources · hover to see the quote

  • Detect unauthenticated VNC connections to libvirt-managed VMs where the VNC password is configured as an empty string — such connections bypass authentication entirely in libvirt < 2.0.0
  • Monitor libvirt QEMU driver VNC sessions that succeed with no authentication (empty credential exchange), particularly on hosts running libvirt versions prior to 2.0.0
  • Alert on VNC authentication bypass: a VNC session established with no password where the libvirt domain XML specifies an empty VNC password attribute
  • ·The vulnerability only manifests when the VNC password in libvirt is explicitly set to an empty string; a VNC server with no password configured at all is a separate condition — the flaw specifically concerns the empty-string case that was documented to disable access but instead grants unauthenticated access
  • ·Only the QEMU driver in libvirt is affected; mingw-libvirt does not enable the vulnerable code path
  • ·Red Hat Enterprise Linux 5 is not affected; RHEL 6 will not receive a fix; RHEL 7 was addressed via RHSA-2016:2577

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.