CVE-2021-41380 describes a denial-of-service vulnerability in RealVNC Viewer 6.21.406, where a remote VNC server can crash the application using crafted RFB protocol data. This medium-severity vulnerability (CVSS 6.5) requires user interaction, specifically social engineering to connect to a malicious server, leading to an application hang rather than data compromise. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.21.406CPE matchmatch criteria | cpe:2.3:a:realvnc:vnc_viewer:6.21.406:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.