PT-2019-2051 · Openbsd+1 · Openssh+1

Publicado

2019-05-01

·

Atualizado

2020-10-13

·

CVE-2019-1859

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Cisco Small Business Switches software (affected versions not specified)
Description A vulnerability in the Secure Shell (SSH) authentication process could allow an attacker to bypass client-side certificate authentication and revert to password authentication. This is due to OpenSSH mishandling the authentication process. An attacker could exploit this by attempting to connect to the device via SSH. A successful exploit could allow the attacker to access the configuration as an administrative user if the default credentials are not changed.
Recommendations For all affected versions, disable client-side certificate authentication and use strong password authentication as a mitigation measure. If client-side certificate authentication is enabled, consider disabling it until a patch is available. Use strong password authentication to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authorization

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-01796
CVE-2019-1859

Produtos afetados

Cisco Small Business Switches
Openssh