Vulnerability CVE-2001-0553


Published: 2001-08-14   Modified: 2012-02-12

Description:
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.

CVSS2 => (AV:L/AC:L/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.2/10
10/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
SSH -> Secure shell 

 References:
http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html
http://www.ciac.org/ciac/bulletins/l-121.shtml
http://www.kb.cert.org/vuls/id/737451
http://www.securityfocus.com/bid/3078
http://www.ssh.com/products/ssh/exploit.cfm
https://exchange.xforce.ibmcloud.com/vulnerabilities/6868

Copyright 2024, cxsecurity.com

 

Back to Top