PT-2025-2799 · Unknown · Eugeny Tabby
0X07E5
·
Published
2025-01-16
·
Updated
2025-01-18
·
CVE-2024-48460
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P |
Name of the Vulnerable Software and Affected Versions:
Eugeny Tabby version 1.0.213
Description:
The issue allows a remote attacker to obtain sensitive information via the server. It sends the SSH
username and password even when the host key verification fails. This could potentially expose confidential data.Recommendations:
For Eugeny Tabby version 1.0.213, as a temporary workaround, consider restricting access to the SSH server until a patch is available. Avoid using the
username and password in the affected SSH connection until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Improper Certificate Validation
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eugeny Tabby