PT-2006-5124 · Ssh+1 · Ssh Tectia Client/Server/Connector+3

Published

2006-08-23

·

Updated

2017-07-20

·

CVE-2006-4315

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1 SSH Tectia Client/Server versions prior to 4.4.5 SSH Tectia Manager versions prior to 2.12
Description The issue is related to an unquoted Windows search path vulnerability in SSH Tectia products when running on Windows. This might allow local users to gain privileges via a malicious program file under "Program Files" or its subdirectories.
Recommendations For SSH Tectia Client/Server/Connector versions 5.0.0 through 5.0.1, update to a version later than 5.0.1. For SSH Tectia Client/Server versions prior to 4.4.5, update to version 4.4.5 or later. For SSH Tectia Manager versions prior to 2.12, update to version 2.12 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4315

Affected Products

Ssh Tectia Client/Server
Ssh Tectia Client/Server/Connector
Ssh Tectia Manager
Windows