← Back

CVE-2001-1476

nvd nist
Published: Jan 18, 2001Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

Affected (8)

Products: Ssh: Ssh
1 product
Ssh
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Ssh
Version 1.2.24
Version 1.2.25
Version 1.2.26
Version 1.2.27
Version 1.2.28
Version 1.2.29
Version 1.2.30
Version 1.2.31

References (4)

Source: cve@mitre.org
ExploitPatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.