Description
ssh-keygen in ssh 1.2.27 - 1.2.30 with Secure-RPC can allow local attackers to recover a SUN-DES-1 magic phrase generated by another user, which the attacker can use to decrypt that user's private key file.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Richard Silverman · clocalunix
https://www.exploit-db.com/exploits/20560
References (4)
Scores
EPSS
0.0058
EPSS Percentile
69.1%
Details
Status
published
Products (4)
ssh/ssh
1.2.27
ssh/ssh
1.2.28
ssh/ssh
1.2.29
ssh/ssh
1.2.30
Published
Jun 02, 2001
Tracked Since
Feb 18, 2026