PT-2001-2556 · Vandyke · Securecrt
Publicado
2001-12-30
·
Atualizado
2017-07-11
·
CVE-2001-1466
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
VanDyke SecureCRT versions prior to 3.4.2
Description
The issue allows remote attackers to execute arbitrary code via a long
username or password when using the SSH-1 protocol.Recommendations
For versions prior to 3.4.2, update to version 3.4.2 or later to resolve the issue. As a temporary workaround, consider restricting the use of the SSH-1 protocol until a patch is applied. Avoid using long
username or password values in the affected protocol to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Securecrt