Vulnerabilities > CVE-2004-2486 - Authentication vulnerability in Dropbear SSH Server Digital Signature Standard

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
dropbear-ssh-project
nessus

Summary

The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.

Nessus

NASL familyGain a shell remotely
NASL idDROPBEAR_SSH.NASL
descriptionThe remote host is running Dropbear prior to version 0.43. There is a flaw in this version of Dropbear that could enable a remote attacker to gain control of the system from a remote location.
last seen2020-06-01
modified2020-06-02
plugin id14234
published2004-08-09
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/14234
titleDropbear SSH Server DSS Verification Failure Remote Privilege Escalation