PT-2001-2556 · Vandyke · Securecrt

Publicado

2001-12-30

·

Atualizado

2017-07-11

·

CVE-2001-1466

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VanDyke SecureCRT versions prior to 3.4.2
Description The issue allows remote attackers to execute arbitrary code via a long username or password when using the SSH-1 protocol.
Recommendations For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the SSH-1 protocol until a patch is applied. Avoid using long username or password values in the affected protocol to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2001-1466

Produtos afetados

Securecrt