Vulnerability Description
JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Jscape | Secure Ftp Applet | <= 4.8.0 |
Related Weaknesses (CWE)
References
- http://secunia.com/advisories/30822Vendor Advisory
- http://securityreason.com/securityalert/4606
- http://www.jscape.com/sftpapplet/docs/HTML/index.html?introhistory.html
- http://www.securityfocus.com/archive/1/493569/100/0/threaded
- http://www.securityfocus.com/archive/1/493652/100/0/threaded
- http://www.securityfocus.com/bid/29882
- http://www.securitytracker.com/id?1020346
- http://www.vupen.com/english/advisories/2008/1919/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43300
- http://secunia.com/advisories/30822Vendor Advisory
- http://securityreason.com/securityalert/4606
- http://www.jscape.com/sftpapplet/docs/HTML/index.html?introhistory.html
- http://www.securityfocus.com/archive/1/493569/100/0/threaded
- http://www.securityfocus.com/archive/1/493652/100/0/threaded
- http://www.securityfocus.com/bid/29882
FAQ
What is CVE-2008-5124?
CVE-2008-5124 is a vulnerability with a CVSS score of 7.5 (HIGH). JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.
How severe is CVE-2008-5124?
CVE-2008-5124 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-5124?
Check the references section above for vendor advisories and patch information. Affected products include: Jscape Secure Ftp Applet.