20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0mailing list
http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html CVE-2001-0553
SSH2 3.0 - Short Password Login
Record summary
CVE-2001-0553 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBSSH2 3.0 - Short Password LoginExploitDB exploitby hypoclearNot analyzed1 file
References
8L-121Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/l-121.shtml VU#737451Third-party advisory
http://www.kb.cert.org/vuls/id/737451 586vdb entry
http://www.osvdb.org/586 3078vdb entry
http://www.securityfocus.com/bid/3078 ssh.comConfirmation
http://www.ssh.com/products/ssh/exploit.cfm ssh-password-length-unauth-access(6868)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/6868 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2001-0553