CVE-2021-44425
An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also…
Does this matter?
Lower severity and a low EPSS score (0.59%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.59% probability · 47th percentile
- CISA KEV
- Not listed
- Affected
- anydesk/anydesk
- Source
- cve@mitre.org
References
- https://anydesk.com/en/downloads/windowsProduct, Vendor Advisory
- https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/Exploit, Third Party Advisory
- https://anydesk.com/en/downloads/windowsProduct, Vendor Advisory
- https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.