Vulnerability CVE-2018-9853


Published: 2018-07-10

Description:
Insecure access control in freeSSHd version 1.3.1 allows attackers to obtain the privileges of the freesshd.exe process by leveraging the ability to login to an unprivileged account on the server.

Type:

CWE-269

(Improper Privilege Management)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
7.5/10
6.4/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Freesshd -> Freesshd 

 References:
https://medium.com/@TheWindowsTwin/vulnerability-in-freesshd-5a0abc147d7a

Copyright 2024, cxsecurity.com

 

Back to Top