PT-2002-2370 · Ssh · Ssh Secure Shell For Servers

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1646

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SSH Secure Shell for Servers versions 3.0.0 through 3.1.1
Description The issue allows remote attackers to override the AllowedAuthentications configuration, enabling the use of less secure authentication schemes, such as password authentication, even if the server is configured to use more secure methods.
Recommendations For versions 3.0.0 through 3.1.1, update the configuration to explicitly disable less secure authentication schemes and ensure that only configured secure authentication methods are used. As a temporary workaround, consider restricting access to the SSH server until a more secure configuration can be implemented.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1646

Affected Products

Ssh Secure Shell For Servers