Vulnerability Description
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ssh | Ssh | 1.2.24 |
References
- http://www.kb.cert.org/vuls/id/565052ExploitPatchUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6490
- http://www.kb.cert.org/vuls/id/565052ExploitPatchUS Government Resource
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6490
FAQ
What is CVE-2001-1476?
CVE-2001-1476 is a vulnerability with a CVSS score of 7.5 (HIGH). SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain m...
How severe is CVE-2001-1476?
CVE-2001-1476 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2001-1476?
Check the references section above for vendor advisories and patch information. Affected products include: Ssh Ssh.