xrdp is an open source RDP server. xrdp versions prior to 0.10.0 have a vulnerability that allows attackers to make an infinite number of login attempts. The number of max login attempts is supposed to be limited by a configuration parameter `MaxLoginRetry` in `/etc/xrdp/sesman.ini`. However, this mechanism was not effectively working. As a result, xrdp allows an infinite number of login attempts.
CVSS Details
- CVSS 3.1 Base Score: 7.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade xrdp | May 15, 2025 | Jul 12, 2024 |
| Suse | — | Upgrade librfxencode0Upgrade xrdpUpgrade libpainter0Upgrade xrdp-devel | Dec 5, 2025 | Feb 3, 2025 |
| Ubuntu | — | Upgrade xrdp (Ubuntu Pro)Upgrade xrdp-pulseaudio-installer (Ubuntu Pro)Upgrade xrdpUpgrade xorgxrdp (Ubuntu Pro) | Jun 28, 2026 | Jun 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub