SSH records
47 published records for vendor ssh.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 4.3%
- Pre-auth RCE
- 2
- With a fix record
- 8.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-310 Cryptographic Issues3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-400 Uncontrolled Resource Consumption1
The weakness classes this vendor ships most often: where to look.
CWEAll records
47 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
50Plan | CVE-2001-0144Proof of concept | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Critical10.0 | — | 32.4% | Mar 12, 2001 |
48Plan | CVE-2012-5975Weaponized | The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 throssh · tectia server · CWE-287 | Critical9.3 | — | 35.9% | Dec 4, 2012 |
42Plan | CVE-2002-1645No exploit | Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbissh · ssh2 | Critical10.0 | — | 7.9% | Nov 25, 2002 |
40Plan | CVE-1999-0248No exploit | A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.ssh · ssh | Critical10.0 | — | 1.6% | Jan 1, 1999 |
36Monitor | CVE-2024-30170No exploit | PrivX before 34.0 allows data exfiltration and denial of service via the REST API.ssh · privx · CWE-400 | Critical9.1 | — | 0.6% | Aug 6, 2024 |
35Monitor | CVE-2021-27891No exploit | SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.ssh · tectia client | High8.8 | — | 1.0% | Mar 15, 2021 |
33Monitor | CVE-1999-0013No exploit | Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent ussh · ssh · CWE-522 | High8.4 | — | 1.1% | Jan 22, 1998 |
32Monitor | CVE-2001-0572No exploit | The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attackerssh · ssh | High7.5 | — | 7.1% | Aug 22, 2001 |
32Monitor | CVE-2001-1473Proof of concept | The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by cssh · ssh · CWE-310 | High7.5 | — | 6.3% | Jan 18, 2001 |
32Monitor | CVE-2001-0471Proof of concept | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to cossh · ssh | High7.5 | — | 5.6% | Jun 27, 2001 |
32Monitor | CVE-2011-0766No exploit | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14erlang · crypto · CWE-310 | High7.8 | — | 3.1% | May 31, 2011 |
31Monitor | CVE-2002-1646No exploit | SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less securessh · secure shell for servers | High7.5 | — | 3.6% | Dec 31, 2002 |
31Monitor | CVE-2021-27892No exploit | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.ssh · tectia client | High7.8 | — | 0.3% | Mar 15, 2021 |
30Monitor | CVE-1999-1029No exploit | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allssh · ssh2 | High7.5 | — | 1.6% | May 13, 1999 |
30Monitor | CVE-2001-1475No exploit | SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generassh · ssh | High7.5 | — | 1.5% | Jan 18, 2001 |
30Monitor | CVE-1999-0310No exploit | SSH 1.2.25 on HP-UX allows access to new user accounts.ssh · ssh | High7.5 | — | 1.5% | Sep 1, 1998 |
30Monitor | CVE-2005-4310No exploit | SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.ssh · tectia server | High7.5 | — | 1.4% | Dec 16, 2005 |
30Monitor | CVE-2001-1476No exploit | SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portionsssh · ssh | High7.5 | — | 1.0% | Jan 18, 2001 |
28Monitor | CVE-2001-0553Proof of concept | SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gassh · secure shell | High7.2 | — | 1.3% | Aug 14, 2001 |
28Monitor | CVE-2007-5616No exploit | ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privilegesssh · tectia client | High7.2 | — | 0.9% | Jan 9, 2008 |
28Monitor | CVE-2002-1715Proof of concept | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to ssh · ssh | High7.2 | — | 0.9% | Dec 31, 2002 |
28Monitor | CVE-2000-0575No exploit | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who ssh · ssh | High7.2 | — | 0.8% | Jul 5, 2000 |
28Monitor | CVE-2002-1644No exploit | SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid tossh · ssh2 | High7.2 | — | 0.4% | Nov 25, 2002 |
28Monitor | CVE-2021-27893No exploit | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.ssh · tectia client | High7.0 | — | 0.4% | Mar 15, 2021 |
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2001-014450Plan
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
CriticalCVSS 10.0Proof of conceptEPSS 32%ssh · sshMar 12, 2001
- CVE-2012-597548Plan
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 thro
CriticalCVSS 9.3WeaponizedEPSS 36%ssh · tectia serverDec 4, 2012
- CVE-2002-164542Plan
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbi
CriticalCVSS 10.0No exploitEPSS 8%ssh · ssh2Nov 25, 2002
- CVE-1999-024840Plan
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
CriticalCVSS 10.0No exploitEPSS 2%ssh · sshJan 1, 1999
- CVE-2024-3017036Monitor
PrivX before 34.0 allows data exfiltration and denial of service via the REST API.
CriticalCVSS 9.1No exploitEPSS 1%ssh · privxAug 6, 2024
- CVE-2021-2789135Monitor
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.
HighCVSS 8.8No exploitEPSS 1%ssh · tectia clientMar 15, 2021
- CVE-1999-001333Monitor
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent u
HighCVSS 8.4No exploitEPSS 1%ssh · sshJan 22, 1998
- CVE-2001-057232Monitor
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker
HighCVSS 7.5No exploitEPSS 7%ssh · sshAug 22, 2001
- CVE-2001-147332Monitor
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by c
HighCVSS 7.5Proof of conceptEPSS 6%ssh · sshJan 18, 2001
- CVE-2001-047132Monitor
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to co
HighCVSS 7.5Proof of conceptEPSS 6%ssh · sshJun 27, 2001
- CVE-2011-076632Monitor
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14
HighCVSS 7.8No exploitEPSS 3%erlang · cryptoMay 31, 2011
- CVE-2002-164631Monitor
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure
HighCVSS 7.5No exploitEPSS 4%ssh · secure shell for serversDec 31, 2002
- CVE-2021-2789231Monitor
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.
HighCVSS 7.8No exploitEPSS 0%ssh · tectia clientMar 15, 2021
- CVE-1999-102930Monitor
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, all
HighCVSS 7.5No exploitEPSS 2%ssh · ssh2May 13, 1999
- CVE-2001-147530Monitor
SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is genera
HighCVSS 7.5No exploitEPSS 2%ssh · sshJan 18, 2001
- CVE-1999-031030Monitor
SSH 1.2.25 on HP-UX allows access to new user accounts.
HighCVSS 7.5No exploitEPSS 2%ssh · sshSep 1, 1998
- CVE-2005-431030Monitor
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
HighCVSS 7.5No exploitEPSS 1%ssh · tectia serverDec 16, 2005
- CVE-2001-147630Monitor
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions
HighCVSS 7.5No exploitEPSS 1%ssh · sshJan 18, 2001
- CVE-2001-055328Monitor
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to ga
HighCVSS 7.2Proof of conceptEPSS 1%ssh · secure shellAug 14, 2001
- CVE-2007-561628Monitor
ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges
HighCVSS 7.2No exploitEPSS 1%ssh · tectia clientJan 9, 2008
- CVE-2002-171528Monitor
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to
HighCVSS 7.2Proof of conceptEPSS 1%ssh · sshDec 31, 2002
- CVE-2000-057528Monitor
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who
HighCVSS 7.2No exploitEPSS 1%ssh · sshJul 5, 2000
- CVE-2002-164428Monitor
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to
HighCVSS 7.2No exploitEPSS 0%ssh · ssh2Nov 25, 2002
- CVE-2021-2789328Monitor
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.
HighCVSS 7.0No exploitEPSS 0%ssh · tectia clientMar 15, 2021