7.5

CVE-2001-1476

Exploit

SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions of user passwords by replaying user sessions with certain modifications, which trigger different messages depending on whether the guess is correct or not.

Data is provided by the National Vulnerability Database (NVD)
SshSsh Version1.2.24
SshSsh Version1.2.25
SshSsh Version1.2.26
SshSsh Version1.2.27
SshSsh Version1.2.28
SshSsh Version1.2.29
SshSsh Version1.2.30
SshSsh Version1.2.31
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.36% 0.549
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P