7.5

CVE-2001-1476

Exploit

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SshSsh Version1.2.24
SshSsh Version1.2.25
SshSsh Version1.2.26
SshSsh Version1.2.27
SshSsh Version1.2.28
SshSsh Version1.2.29
SshSsh Version1.2.30
SshSsh Version1.2.31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.36% 0.549
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P