Записи SSH
47 опубликованных записей вендора ssh.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 4,3 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 8,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-310 Cryptographic Issues3
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-287 Improper Authentication1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-400 Uncontrolled Resource Consumption1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
47 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
50В плане | CVE-2001-0144Proof of concept | CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an inssh · ssh | Критическая10,0 | — | 32,4 % | 12 мар. 2001 г. |
48В плане | CVE-2012-5975Готовый эксплойт | The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 throssh · tectia server · CWE-287 | Критическая9,3 | — | 35,9 % | 4 дек. 2012 г. |
42В плане | CVE-2002-1645Эксплойта нет | Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbissh · ssh2 | Критическая10,0 | — | 7,9 % | 25 нояб. 2002 г. |
40В плане | CVE-1999-0248Эксплойта нет | A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.ssh · ssh | Критическая10,0 | — | 1,6 % | 1 янв. 1999 г. |
36Наблюдать | CVE-2024-30170Эксплойта нет | PrivX before 34.0 allows data exfiltration and denial of service via the REST API.ssh · privx · CWE-400 | Критическая9,1 | — | 0,6 % | 6 авг. 2024 г. |
35Наблюдать | CVE-2021-27891Эксплойта нет | SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.ssh · tectia client | Высокая8,8 | — | 1,0 % | 15 мар. 2021 г. |
33Наблюдать | CVE-1999-0013Эксплойта нет | Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent ussh · ssh · CWE-522 | Высокая8,4 | — | 1,1 % | 22 янв. 1998 г. |
32Наблюдать | CVE-2001-0572Эксплойта нет | The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attackerssh · ssh | Высокая7,5 | — | 7,1 % | 22 авг. 2001 г. |
32Наблюдать | CVE-2001-1473Proof of concept | The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by cssh · ssh · CWE-310 | Высокая7,5 | — | 6,3 % | 18 янв. 2001 г. |
32Наблюдать | CVE-2001-0471Proof of concept | SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to cossh · ssh | Высокая7,5 | — | 5,6 % | 27 июн. 2001 г. |
32Наблюдать | CVE-2011-0766Эксплойта нет | The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14erlang · crypto · CWE-310 | Высокая7,8 | — | 3,1 % | 31 мая 2011 г. |
31Наблюдать | CVE-2002-1646Эксплойта нет | SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less securessh · secure shell for servers | Высокая7,5 | — | 3,6 % | 31 дек. 2002 г. |
31Наблюдать | CVE-2021-27892Эксплойта нет | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.ssh · tectia client | Высокая7,8 | — | 0,3 % | 15 мар. 2021 г. |
30Наблюдать | CVE-1999-1029Эксплойта нет | SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allssh · ssh2 | Высокая7,5 | — | 1,6 % | 13 мая 1999 г. |
30Наблюдать | CVE-2001-1475Эксплойта нет | SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generassh · ssh | Высокая7,5 | — | 1,5 % | 18 янв. 2001 г. |
30Наблюдать | CVE-1999-0310Эксплойта нет | SSH 1.2.25 on HP-UX allows access to new user accounts.ssh · ssh | Высокая7,5 | — | 1,5 % | 1 сент. 1998 г. |
30Наблюдать | CVE-2005-4310Эксплойта нет | SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.ssh · tectia server | Высокая7,5 | — | 1,4 % | 16 дек. 2005 г. |
30Наблюдать | CVE-2001-1476Эксплойта нет | SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portionsssh · ssh | Высокая7,5 | — | 1,0 % | 18 янв. 2001 г. |
28Наблюдать | CVE-2001-0553Proof of concept | SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gassh · secure shell | Высокая7,2 | — | 1,3 % | 14 авг. 2001 г. |
28Наблюдать | CVE-2007-5616Эксплойта нет | ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privilegesssh · tectia client | Высокая7,2 | — | 0,9 % | 9 янв. 2008 г. |
28Наблюдать | CVE-2002-1715Proof of concept | SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to ssh · ssh | Высокая7,2 | — | 0,9 % | 31 дек. 2002 г. |
28Наблюдать | CVE-2000-0575Эксплойта нет | SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who ssh · ssh | Высокая7,2 | — | 0,8 % | 5 июл. 2000 г. |
28Наблюдать | CVE-2002-1644Эксплойта нет | SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid tossh · ssh2 | Высокая7,2 | — | 0,4 % | 25 нояб. 2002 г. |
28Наблюдать | CVE-2021-27893Эксплойта нет | SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.ssh · tectia client | Высокая7,0 | — | 0,4 % | 15 мар. 2021 г. |
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2001-014450В плане
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an in
КритическаяCVSS 10,0Proof of conceptEPSS 32 %ssh · ssh12 мар. 2001 г.
- CVE-2012-597548В плане
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 thro
КритическаяCVSS 9,3Готовый эксплойтEPSS 36 %ssh · tectia server4 дек. 2012 г.
- CVE-2002-164542В плане
Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbi
КритическаяCVSS 10,0Эксплойта нетEPSS 8 %ssh · ssh225 нояб. 2002 г.
- CVE-1999-024840В плане
A race condition in the authentication agent mechanism of sshd 1.2.17 allows an attacker to steal another user's credentials.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %ssh · ssh1 янв. 1999 г.
- CVE-2024-3017036Наблюдать
PrivX before 34.0 allows data exfiltration and denial of service via the REST API.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %ssh · privx6 авг. 2024 г.
- CVE-2021-2789135Наблюдать
SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %ssh · tectia client15 мар. 2021 г.
- CVE-1999-001333Наблюдать
Stolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent u
ВысокаяCVSS 8,4Эксплойта нетEPSS 1 %ssh · ssh22 янв. 1998 г.
- CVE-2001-057232Наблюдать
The SSH protocols 1 and 2 (aka SSH-2) as implemented in OpenSSH and other packages have various weaknesses which can allow a remote attacker
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %ssh · ssh22 авг. 2001 г.
- CVE-2001-147332Наблюдать
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by c
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %ssh · ssh18 янв. 2001 г.
- CVE-2001-047132Наблюдать
SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to co
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %ssh · ssh27 июн. 2001 г.
- CVE-2011-076632Наблюдать
The random number generator in the Crypto application before 2.0.2.2, and SSH before 2.0.5, as used in the Erlang/OTP ssh library before R14
ВысокаяCVSS 7,8Эксплойта нетEPSS 3 %erlang · crypto31 мая 2011 г.
- CVE-2002-164631Наблюдать
SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %ssh · secure shell for servers31 дек. 2002 г.
- CVE-2021-2789231Наблюдать
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %ssh · tectia client15 мар. 2021 г.
- CVE-1999-102930Наблюдать
SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, all
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ssh · ssh213 мая 1999 г.
- CVE-2001-147530Наблюдать
SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is genera
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ssh · ssh18 янв. 2001 г.
- CVE-1999-031030Наблюдать
SSH 1.2.25 on HP-UX allows access to new user accounts.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %ssh · ssh1 сент. 1998 г.
- CVE-2005-431030Наблюдать
SSH Tectia Server 5.0.0 (A, F, and T), when allowing host-based authentication only, allows users to log in with the wrong credentials.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ssh · tectia server16 дек. 2005 г.
- CVE-2001-147630Наблюдать
SSH before 2.0, with RC4 encryption and the "disallow NULL passwords" option enabled, makes it easier for remote attackers to guess portions
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %ssh · ssh18 янв. 2001 г.
- CVE-2001-055328Наблюдать
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to ga
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %ssh · secure shell14 авг. 2001 г.
- CVE-2007-561628Наблюдать
ssh-signer in SSH Tectia Client and Server 5.x before 5.2.4, and 5.3.x before 5.3.6, on Unix and Linux allows local users to gain privileges
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ssh · tectia client9 янв. 2008 г.
- CVE-2002-171528Наблюдать
SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to
ВысокаяCVSS 7,2Proof of conceptEPSS 1 %ssh · ssh31 дек. 2002 г.
- CVE-2000-057528Наблюдать
SSH 1.2.27 with Kerberos authentication support stores Kerberos tickets in a file which is created in the current directory of the user who
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %ssh · ssh5 июл. 2000 г.
- CVE-2002-164428Наблюдать
SSH Secure Shell for Servers and SSH Secure Shell for Workstations 2.0.13 through 3.2.1, when running without a PTY, does not call setsid to
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %ssh · ssh225 нояб. 2002 г.
- CVE-2021-2789328Наблюдать
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions.
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %ssh · tectia client15 мар. 2021 г.