CVE-2001-0553
Summary
| CVE | CVE-2001-0553 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2001-08-14 04:00:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use "NP" in the password field. |
Risk And Classification
Primary CVSS: v2.0 7.2 from [email protected]
AV:L/AC:L/Au:N/C:C/I:C/A:C
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ssh | Secure Shell | 3.0.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 Not Found | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| CERT/CC Vulnerability Note VU#737451 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| Page Not Found. Sorry about that! | af854a3a-2127-422b-91ae-364da2661108 | www.ssh.com | |
| SSH Short Password Login Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Neohapsis Archives - Bugtraq - URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0 - From [email protected] | af854a3a-2127-422b-91ae-364da2661108 | archives.neohapsis.com | Exploit, Patch, Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| SSH Secure Shell Remote Root Exploit Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.ciac.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.