
Cloud Vulnerability DB
A community-led vulnerabilities database
In the xrdp package (in branches through 3.14) for Alpine Linux, a security vulnerability was identified and assigned CVE-2021-36158. The vulnerability was discovered and reported on July 5, 2021, affecting RDP sessions due to the use of pre-generated RSA certificates and private keys (NVD, MITRE).
The vulnerability stems from the xrdp package containing default cryptographic keys that are generated at build-time. This means that every system using the package shares the same private key and certificate files, specifically located at /etc/xrdp/key.pem, /etc/xrdp/cert.pem, and /etc/rsakeys.ini (Alpine Issue).
The use of pre-generated RSA certificates and private keys makes RDP sessions vulnerable to man-in-the-middle attacks. Since the same cryptographic materials are shared across all installations, an attacker who obtains these keys could potentially intercept and decrypt RDP session traffic between affected systems (NVD).
The vulnerability is particularly concerning because the compromised keys are publicly available through the package distribution, making exploitation straightforward for any attacker aware of the issue (Alpine Issue).
The issue was addressed in various distributions, with Debian implementing fixes in multiple versions including bullseye (0.9.21.1-1~deb11u1), bookworm (0.9.21.1-1), and sid/trixie (0.10.1-3). A suggested solution involves moving the key generation process to the post-install phase, ensuring unique keys are generated for each installation (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."