CVE-2013-6765: Openvas Manager
High severity, CVSS 7.5. EPSS: 7.3% chance of exploitation in the next 30 days.
OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.
Affected products
- Openvas Openvas Manager: version 4.0 only; version 4.0.0 only; version 4.0.1 only; version 4.0.2 only; version 4.0.3 only; version 3.0 only; …
Published 2014-05-19. Last modified 2026-06-17.