Loading
WinVNC 3.3.3 and earlier generates the same challenge string for multiple connections, which allows remote attackers to bypass VNC authentication by sniffing the challenge and response of other users.
Use Att vendor hub and Winvnc product page to widen CVE-2001-1422 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2001-0168, CVE-2000-1164 and CVE-2001-0167 for nearby disclosures in the same product family.