7.5
CVSSv2

CVE-2001-1476

Published: 18/01/2001 Updated: 11/07/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SSH prior to 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote malicious users to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

Vulnerable Product Search on Vulmon Subscribe to Product

ssh ssh 1.2.27

ssh ssh 1.2.28

ssh ssh 1.2.29

ssh ssh 1.2.30

ssh ssh 1.2.25

ssh ssh 1.2.26

ssh ssh 1.2.24

ssh ssh 1.2.31