CVE-2024-47857

CRITICAL

SSH Communication Security PrivX 18.0-36.0 - Account Impersonation via Public Key Signature Validation Bypass

Title source: llm
STIX 2.1

Description

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts to which the "account B" has access.

References (2)

Core 2
Core References
Various Sources
https://ssh.com

Scores

CVSS v3 9.8
EPSS 0.0042
EPSS Percentile 33.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Published Jan 31, 2025
Tracked Since Feb 18, 2026