CVE-2013-6766: Openvas Administrator
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
OpenVAS Administrator 1.2 before 1.2.2 and 1.3 before 1.3.2 allows remote attackers to bypass the OAP authentication restrictions and execute OAP commands via a crafted OAP request for version information, which causes the state to be set to CLIENT_AUTHENTIC.
Affected products
- Openvas Openvas Administrator: version 1.2 only; version 1.2.0 only; version 1.2.1 only; version 1.3 only; version 1.3.0 only; version 1.3.1 only
Published 2014-05-19. Last modified 2026-06-17.