{"api_version":"1","generated_at":"2026-07-23T03:25:28+00:00","cve":"CVE-2003-0786","urls":{"html":"https://cve.report/CVE-2003-0786","api":"https://cve.report/api/cve/CVE-2003-0786.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2003-0786","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2003-0786"},"summary":{"title":"CVE-2003-0786","description":"The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.","state":"PUBLISHED","assigner":"mitre","published_at":"2003-11-17 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/338616","name":"http://www.securityfocus.com/archive/1/338616","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/338617","name":"http://www.securityfocus.com/archive/1/338617","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openssh.com/txt/sshpam.adv","name":"http://www.openssh.com/txt/sshpam.adv","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/602204","name":"http://www.kb.cert.org/vuls/id/602204","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"CERT/CC Vulnerability Note VU#602204","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html","name":"http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[Full-Disclosure] [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/8677","name":"http://www.securityfocus.com/bid/8677","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Multiple Portable OpenSSH PAM Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2003-0786","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2003-0786","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2003","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbsd","cpe5":"openssh","cpe6":"3.7.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2003","cve_id":"786","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbsd","cpe5":"openssh","cpe6":"3.7.1p1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:05:12.644Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.openssh.com/txt/sshpam.adv"},{"name":"8677","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/8677"},{"name":"20030923 Multiple PAM vulnerabilities in portable OpenSSH","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/338617"},{"name":"20030923 Portable OpenSSH 3.7.1p2 released","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/338616"},{"name":"20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html"},{"name":"VU#602204","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/602204"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2003-09-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-03-21T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.openssh.com/txt/sshpam.adv"},{"name":"8677","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/8677"},{"name":"20030923 Multiple PAM vulnerabilities in portable OpenSSH","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/338617"},{"name":"20030923 Portable OpenSSH 3.7.1p2 released","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/338616"},{"name":"20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html"},{"name":"VU#602204","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/602204"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2003-0786","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.openssh.com/txt/sshpam.adv","refsource":"CONFIRM","url":"http://www.openssh.com/txt/sshpam.adv"},{"name":"8677","refsource":"BID","url":"http://www.securityfocus.com/bid/8677"},{"name":"20030923 Multiple PAM vulnerabilities in portable OpenSSH","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/338617"},{"name":"20030923 Portable OpenSSH 3.7.1p2 released","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/338616"},{"name":"20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh)","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2003-September/010812.html"},{"name":"VU#602204","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/602204"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2003-0786","datePublished":"2003-09-25T04:00:00.000Z","dateReserved":"2003-09-17T00:00:00.000Z","dateUpdated":"2024-08-08T02:05:12.644Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2003-11-17 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openbsd:openssh:3.7.1:*:*:*:*:*:*:*","matchCriteriaId":"80DC64F6-FE28-44BA-91D1-EC2DB11B2CFC"},{"vulnerable":true,"criteria":"cpe:2.3:a:openbsd:openssh:3.7.1p1:*:*:*:*:*:*:*","matchCriteriaId":"DF23EBA1-D3A9-413F-9E83-43A91492C031"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2003","CveId":"786","Ordinal":"1","Title":"CVE-2003-0786","CVE":"CVE-2003-0786","Year":"2003"},"notes":[{"CveYear":"2003","CveId":"786","Ordinal":"1","NoteData":"The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.","Type":"Description","Title":"CVE-2003-0786"},{"CveYear":"2003","CveId":"786","Ordinal":"2","NoteData":"2003-09-25","Type":"Other","Title":"Published"},{"CveYear":"2003","CveId":"786","Ordinal":"3","NoteData":"2005-03-21","Type":"Other","Title":"Modified"}]}}}