PT-2024-2650 · Wolfssh · Wolfssh

Published

2024-03-25

·

Updated

2024-03-26

·

CVE-2024-2873

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions wolfSSH versions prior to 1.4.17
Description A vulnerability was found in wolfSSH's server-side state machine. This issue is related to shortcomings in the authentication procedure, allowing a malicious client to create channels without first performing user authentication, resulting in unauthorized access. A remote attacker could exploit this vulnerability to bypass existing security restrictions.
Recommendations For versions prior to 1.4.17, update to version 1.4.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the server-side state machine until a patch is available. Avoid allowing clients to create channels without proper user authentication.

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-02717
CVE-2024-2873

Affected Products

Wolfssh