10
CVSSv2

CVE-2003-0786

Published: 17/11/2003 Updated: 10/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote malicious users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

openbsd openssh 3.7.1p1

openbsd openssh 3.7.1