Vulnerability Description
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ssh | Secure Shell For Servers | 3.0 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.htmlPatch
- http://www.ciac.org/ciac/bulletins/m-081.shtml
- http://www.kb.cert.org/vuls/id/341187US Government Resource
- http://www.securityfocus.com/bid/4810Patch
- http://www.ssh.com/company/newsroom/article/201/
- http://www.ssh.com/products/ssh/advisories/authentication.cfmPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9163
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.htmlPatch
- http://www.ciac.org/ciac/bulletins/m-081.shtml
- http://www.kb.cert.org/vuls/id/341187US Government Resource
- http://www.securityfocus.com/bid/4810Patch
- http://www.ssh.com/company/newsroom/article/201/
- http://www.ssh.com/products/ssh/advisories/authentication.cfmPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9163
FAQ
What is CVE-2002-1646?
CVE-2002-1646 is a vulnerability with a CVSS score of 7.5 (HIGH). SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for ...
How severe is CVE-2002-1646?
CVE-2002-1646 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1646?
Check the references section above for vendor advisories and patch information. Affected products include: Ssh Secure Shell For Servers.