Vulnerabilities > CVE-2002-1646 - Unspecified vulnerability in SSH Secure Shell FOR Servers

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ssh
nessus

Summary

SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.

Nessus

NASL familyMisc.
NASL idSSH_ALLOWEDAUTHENTICATIONS.NASL
descriptionThe remote host is running a version of SSH that is older than 3.1.2 and newer or equal to 3.0.0. There is a vulnerability in this release that may, under some circumstances, allow users to authenticate using a password whereas it is not explicitly listed as a valid authentication mechanism. An attacker may use this flaw to attempt to brute-force a password using a dictionary attack (if the passwords used are weak).
last seen2020-06-01
modified2020-06-02
plugin id10965
published2002-05-24
reporterThis script is Copyright (C) 2002-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/10965
titleSSH 3 AllowedAuthentications Remote Bypass