4.6
CVE-2003-0047
- EPSS 0.08%
- Veröffentlicht 19.02.2003 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Van Dyke Technologies ≫ Entunnel Version <= 1.0.2
Van Dyke Technologies ≫ Securecrt Version3.4.7
Van Dyke Technologies ≫ Securecrt Version4.0.2
Van Dyke Technologies ≫ Securefx Version2.0.4
Van Dyke Technologies ≫ Securefx Version2.1.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.208 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|