SSH Communications Secure Shell Server AllowedAuthentications Configuration Overriding Vulnerability
BID:4810
Info
SSH Communications Secure Shell Server AllowedAuthentications Configuration Overriding Vulnerability
| Bugtraq ID: | 4810 |
| Class: | Design Error |
| CVE: |
CVE-2002-1646 |
| Remote: | Yes |
| Local: | No |
| Published: | May 23 2002 12:00AM |
| Updated: | Jul 11 2009 12:46PM |
| Credit: | Vulnerability announced by SSH Communications Security. |
| Vulnerable: |
SSH Communications Security SSH2 for Win32 3.1.1 SSH Communications Security SSH2 for Win32 3.1 SSH Communications Security SSH2 for Unix 3.1.1 SSH Communications Security SSH2 for Unix 3.1 SSH Communications Security SSH2 3.0.1 SSH Communications Security SSH2 3.0 |
| Not Vulnerable: |
SSH Communications Security SSH2 for Win32 3.1.2 SSH Communications Security SSH2 for Unix 3.1.2 |
Discussion
SSH Communications Secure Shell Server AllowedAuthentications Configuration Overriding Vulnerability
Secure Shell is the commercial SSH implementation distributed and maintained by SSH Communications. It is available for the Unix, Linux, and Microsoft Windows platforms.
Under some circumstances, it may be possible for a remote user to bypass the "AllowedAuthentications" specified in the server configuration. This could allow a user to authenticate using a different or weaker means, such as a password. In such a situation where stronger authentication protocols are in place, and system user accounts have been secured with weak passwords, an attacker may be able to gain access to the system using the weak password, rather than the strong authentcation scheme.
Secure Shell is the commercial SSH implementation distributed and maintained by SSH Communications. It is available for the Unix, Linux, and Microsoft Windows platforms.
Under some circumstances, it may be possible for a remote user to bypass the "AllowedAuthentications" specified in the server configuration. This could allow a user to authenticate using a different or weaker means, such as a password. In such a situation where stronger authentication protocols are in place, and system user accounts have been secured with weak passwords, an attacker may be able to gain access to the system using the weak password, rather than the strong authentcation scheme.
References
SSH Communications Secure Shell Server AllowedAuthentications Configuration Overriding Vulnerability
References:
References:
- Security Advisory Regarding Vulnerability in SSH Secure Shell for Servers (SSH Communications Security)