Vulnerability Description
TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value of the default 4-digit PIN.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Teamviewer | Teamviewer | >= 10.0.2551, <= 13.2.9356 |
References
- https://twitter.com/vah_13/status/1036894081350291457Issue TrackingThird Party Advisory
- https://twitter.com/vah_13/status/1036894081350291457Issue TrackingThird Party Advisory
FAQ
What is CVE-2018-16550?
CVE-2018-16550 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value o...
How severe is CVE-2018-16550?
CVE-2018-16550 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-16550?
Check the references section above for vendor advisories and patch information. Affected products include: Teamviewer Teamviewer.