Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2001-1585

Опубликовано: 31 дек. 2001
Источник: nvd
CVSS2: 6.8
EPSS Низкий

Описание

SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openbsd:openssh:2.3.1:*:*:*:*:*:*:*

EPSS

Процентиль: 50%
0.00265
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

debian
больше 23 лет назад

SSH protocol 2 (aka SSH-2) public key authentication in the developmen ...

github
около 3 лет назад

SSH protocol 2 (aka SSH-2) public key authentication in the development snapshot of OpenSSH 2.3.1, available from 2001-01-18 through 2001-02-08, does not perform a challenge-response step to ensure that the client has the proper private key, which allows remote attackers to bypass authentication as other users by supplying a public key from that user's authorized_keys file.

EPSS

Процентиль: 50%
0.00265
Низкий

6.8 Medium

CVSS2

Дефекты

CWE-287