{"api_version":"1","generated_at":"2026-06-13T12:41:16+00:00","cve":"CVE-2001-0553","urls":{"html":"https://cve.report/CVE-2001-0553","api":"https://cve.report/api/cve/CVE-2001-0553.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2001-0553","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2001-0553"},"summary":{"title":"CVE-2001-0553","description":"SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use \"NP\" in the password field.","state":"PUBLISHED","assigner":"mitre","published_at":"2001-08-14 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.osvdb.org/586","name":"http://www.osvdb.org/586","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"404 Not Found","mime":"text/html","httpstatus":"404","archivestatus":"403"},{"url":"http://www.kb.cert.org/vuls/id/737451","name":"http://www.kb.cert.org/vuls/id/737451","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#737451","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ssh.com/products/ssh/exploit.cfm","name":"http://www.ssh.com/products/ssh/exploit.cfm","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Page Not Found. Sorry about that!","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/3078","name":"http://www.securityfocus.com/bid/3078","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SSH Short Password Login Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html","name":"http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"Neohapsis Archives - Bugtraq - URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0 - From customer.service@ssh.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6868","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6868","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.ciac.org/ciac/bulletins/l-121.shtml","name":"http://www.ciac.org/ciac/bulletins/l-121.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SSH Secure Shell Remote Root Exploit Vulnerability","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2001-0553","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2001-0553","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2001","cve_id":"553","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ssh","cpe5":"secure_shell","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:21:38.670Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.ssh.com/products/ssh/exploit.cfm"},{"name":"ssh-password-length-unauth-access(6868)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6868"},{"name":"VU#737451","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/737451"},{"name":"586","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/586"},{"name":"L-121","tags":["third-party-advisory","government-resource","x_refsource_CIAC","x_transferred"],"url":"http://www.ciac.org/ciac/bulletins/l-121.shtml"},{"name":"3078","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/3078"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2001-07-20T00:00:00.000Z","descriptions":[{"lang":"en","value":"SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use \"NP\" in the password field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-16T00:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.ssh.com/products/ssh/exploit.cfm"},{"name":"ssh-password-length-unauth-access(6868)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6868"},{"name":"VU#737451","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/737451"},{"name":"586","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/586"},{"name":"L-121","tags":["third-party-advisory","government-resource","x_refsource_CIAC"],"url":"http://www.ciac.org/ciac/bulletins/l-121.shtml"},{"name":"3078","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/3078"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2001-0553","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use \"NP\" in the password field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20010720 URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2001-07/0486.html"},{"name":"http://www.ssh.com/products/ssh/exploit.cfm","refsource":"CONFIRM","url":"http://www.ssh.com/products/ssh/exploit.cfm"},{"name":"ssh-password-length-unauth-access(6868)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/6868"},{"name":"VU#737451","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/737451"},{"name":"586","refsource":"OSVDB","url":"http://www.osvdb.org/586"},{"name":"L-121","refsource":"CIAC","url":"http://www.ciac.org/ciac/bulletins/l-121.shtml"},{"name":"3078","refsource":"BID","url":"http://www.securityfocus.com/bid/3078"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2001-0553","datePublished":"2002-06-25T04:00:00.000Z","dateReserved":"2001-07-24T00:00:00.000Z","dateUpdated":"2024-08-08T04:21:38.670Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2001-08-14 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:secure_shell:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"6142908B-4B59-4AB8-8D68-5203DF131D00"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2001","CveId":"553","Ordinal":"1","Title":"CVE-2001-0553","CVE":"CVE-2001-0553","Year":"2001"},"notes":[{"CveYear":"2001","CveId":"553","Ordinal":"1","NoteData":"SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short password fields, such as locked accounts that use \"NP\" in the password field.","Type":"Description","Title":"CVE-2001-0553"},{"CveYear":"2001","CveId":"553","Ordinal":"2","NoteData":"2002-06-25","Type":"Other","Title":"Published"},{"CveYear":"2001","CveId":"553","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}