PT-2002-2370 · Ssh · Ssh Secure Shell For Servers
Published
2002-12-31
·
Updated
2017-07-11
·
CVE-2002-1646
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SSH Secure Shell for Servers versions 3.0.0 through 3.1.1
Description
The issue allows remote attackers to override the AllowedAuthentications configuration, enabling the use of less secure authentication schemes, such as password authentication, even if the server is configured to use more secure methods.
Recommendations
For versions 3.0.0 through 3.1.1, update the configuration to explicitly disable less secure authentication schemes and ensure that only configured secure authentication methods are used. As a temporary workaround, consider restricting access to the SSH server until a more secure configuration can be implemented.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ssh Secure Shell For Servers