Vulnerability record · CVE-2006-2369 · published 15 May 2006
CVE-2006-2369: RealVNC authentication bypass via insecure security type
Vnc · Realvnc
RealVNC 4.1.1 and products embedding it, including AdderLink IP and Cisco CallManager, accept a client-requested insecure security type such as "Type 1 - None" even when the server did not offer it. This lets a remote client skip authentication entirely, and the flaw was originally demonstrated using a long password. It matters because VNC provides direct interactive access to the desktop or console of the affected host.
Description
RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote bypass of VNC authentication with a very high EPSS score and public exploit references, though no KEV listing or confirmed in-the-wild use is stated.
What it is
RealVNC 4.1.1 and products embedding it, including AdderLink IP and Cisco CallManager, accept a client-requested insecure security type such as "Type 1 - None" even when the server did not offer it. This lets a remote client skip authentication entirely, and the flaw was originally demonstrated using a long password. It matters because VNC provides direct interactive access to the desktop or console of the affected host.
Impact
An unauthenticated remote attacker gains interactive access to the VNC session, which typically means control of the desktop or console with the privileges of the logged-in user. The CVSS vector rates partial confidentiality, integrity and availability impact.
Attack surface
Reachable over the network on the VNC service port; no authentication is required because the bypass is the authentication step, and no user interaction is described. Any client able to reach the service can attempt the crafted security-type request.
Exploitation
Not listed in CISA KEV and no ransomware use is documented, but EPSS is very high at 0.92355 (99.8th percentile) and multiple references carry Exploit tags, indicating public exploit material exists. The record does not state whether exploitation is observed in the wild.
What to do
- Patch or upgrade RealVNC and any embedded RealVNC components (AdderLink IP, Cisco CallManager) per the vendor advisories referenced in the record.
- Do not expose VNC services directly to untrusted networks; restrict access to management networks or VPN.
- Enforce strong authentication at the network layer (for example SSH tunneling or a gateway) so a bypassed VNC authentication still faces a second control.
- Where the product allows it, disable or refuse the "None" security type and require a strong authentication type.
- Audit hosts for VNC listeners and confirm the running version is not a vulnerable RealVNC 4.1.1 build.
Detection
- Monitor VNC service logs and network captures for security-type negotiation that selects "None" or Type 1 when the server did not offer it.
- Alert on successful VNC sessions from unexpected source addresses or at unusual times, especially where no authentication event precedes them.
- Inventory and version-scan hosts and embedded devices for RealVNC 4.1.1 or products known to embed it.
- Correlate VNC connection events with subsequent interactive activity on the host to spot post-bypass access.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-2369 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-2369), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.