Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2014-9278

Опубликовано: 06 дек. 2014
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:openbsd:openssh:-:*:*:*:*:*:*:*

Одно из

cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*

EPSS

Процентиль: 57%
0.00351
Низкий

4 Medium

CVSS2

Дефекты

CWE-287

Связанные уязвимости

ubuntu
больше 10 лет назад

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.

redhat
почти 11 лет назад

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.

debian
больше 10 лет назад

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 a ...

github
больше 3 лет назад

The OpenSSH server, as used in Fedora and Red Hat Enterprise Linux 7 and when running in a Kerberos environment, allows remote authenticated users to log in as another user when they are listed in the .k5users file of that user, which might bypass intended authentication requirements that would force a local login.

oracle-oval
больше 10 лет назад

ELSA-2015-0425: openssh security, bug fix and enhancement update (MODERATE)

EPSS

Процентиль: 57%
0.00351
Низкий

4 Medium

CVSS2

Дефекты

CWE-287