{"api_version":"1","generated_at":"2026-07-23T06:14:19+00:00","cve":"CVE-2003-0047","urls":{"html":"https://cve.report/CVE-2003-0047","api":"https://cve.report/api/cve/CVE-2003-0047.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0047","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0047"},"summary":{"title":"CVE-2003-0047","description":"SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-02-19 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.idefense.com/advisory/01.28.03.txt","name":"http://www.idefense.com/advisory/01.28.03.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"iDEFENSE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1006012","name":"http://www.securitytracker.com/id?1006012","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VanDyke Entunnel SSH2 Client Software Access Control Bug May Disclose Passwords to Local Users Via Memory - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6726","name":"http://www.securityfocus.com/bid/6726","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Van Dyke SecureCRT SSH2 Authentication Password Persistence Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1006011","name":"http://www.securitytracker.com/id?1006011","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VanDyke SecureFX SSH2 Client Software Access Control Bug May Disclose Passwords to Local Users Via Memory - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://marc.info/?l=bugtraq&m=104386492422014&w=2","name":"http://marc.info/?l=bugtraq&m=104386492422014&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/6728","name":"http://www.securityfocus.com/bid/6728","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Van Dyke Software Entunnel SSH2 Authentication Password Persistence Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/6727","name":"http://www.securityfocus.com/bid/6727","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Van Dyke Software SecureFX SSH2 Authentication Password Persistence Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securitytracker.com/id?1006010","name":"http://www.securitytracker.com/id?1006010","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"VanDyke SecureCRT SSH2 Client Software Access Control Bug May Disclose Passwords to Local Users Via Memory - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0047","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0047","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"47","vulnerable":"1","versionEndIncluding":"1.0.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"van_dyke_technologies","cpe5":"entunnel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"47","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"van_dyke_technologies","cpe5":"securecrt","cpe6":"3.4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"47","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"van_dyke_technologies","cpe5":"securecrt","cpe6":"4.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"47","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"van_dyke_technologies","cpe5":"securefx","cpe6":"2.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"47","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"van_dyke_technologies","cpe5":"securefx","cpe6":"2.1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T01:43:35.246Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=104386492422014&w=2"},{"name":"6727","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6727"},{"name":"6728","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6728"},{"name":"1006011","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1006011"},{"name":"1006010","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1006010"},{"name":"1006012","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1006012"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.idefense.com/advisory/01.28.03.txt"},{"name":"6726","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6726"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-01-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=104386492422014&w=2"},{"name":"6727","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6727"},{"name":"6728","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6728"},{"name":"1006011","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1006011"},{"name":"1006010","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1006010"},{"name":"1006012","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1006012"},{"tags":["x_refsource_MISC"],"url":"http://www.idefense.com/advisory/01.28.03.txt"},{"name":"6726","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6726"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0047","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20030129 iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=104386492422014&w=2"},{"name":"6727","refsource":"BID","url":"http://www.securityfocus.com/bid/6727"},{"name":"6728","refsource":"BID","url":"http://www.securityfocus.com/bid/6728"},{"name":"1006011","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1006011"},{"name":"1006010","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1006010"},{"name":"1006012","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1006012"},{"name":"http://www.idefense.com/advisory/01.28.03.txt","refsource":"MISC","url":"http://www.idefense.com/advisory/01.28.03.txt"},{"name":"6726","refsource":"BID","url":"http://www.securityfocus.com/bid/6726"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0047","datePublished":"2003-02-01T05:00:00.000Z","dateReserved":"2003-01-28T00:00:00.000Z","dateUpdated":"2024-08-08T01:43:35.246Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-02-19 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:van_dyke_technologies:entunnel:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.2","matchCriteriaId":"503444E8-431B-48A9-BF7E-A8DD3FF47E0A"},{"vulnerable":true,"criteria":"cpe:2.3:a:van_dyke_technologies:securecrt:3.4.7:*:*:*:*:*:*:*","matchCriteriaId":"9F4B4CAB-77BB-49F4-B72D-C077DB8803B6"},{"vulnerable":true,"criteria":"cpe:2.3:a:van_dyke_technologies:securecrt:4.0.2:*:*:*:*:*:*:*","matchCriteriaId":"FC7CC992-1650-40C4-9465-A4B3DB6689C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:van_dyke_technologies:securefx:2.0.4:*:*:*:*:*:*:*","matchCriteriaId":"BD1D6B50-6F7E-4750-BC24-22F823E34454"},{"vulnerable":true,"criteria":"cpe:2.3:a:van_dyke_technologies:securefx:2.1.2:*:*:*:*:*:*:*","matchCriteriaId":"0858A846-9044-4360-A214-A4F7785532CF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"47","Ordinal":"1","Title":"CVE-2003-0047","CVE":"CVE-2003-0047","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"47","Ordinal":"1","NoteData":"SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.","Type":"Description","Title":"CVE-2003-0047"},{"CveYear":"2003","CveId":"47","Ordinal":"2","NoteData":"2003-02-01","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"47","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}