freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
BID:56785
Info
freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
| Bugtraq ID: | 56785 |
| Class: | Access Validation Error |
| CVE: |
CVE-2012-6066 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 03 2012 12:00AM |
| Updated: | Apr 02 2013 03:47PM |
| Credit: | Kingcope |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
freeSSHd is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
freeSSHd 2.1.3 is vulnerable; other versions may also be affected.
freeSSHd is prone to an authentication-bypass vulnerability.
Remote attackers can exploit this issue to bypass the authentication mechanism and gain unauthorized access.
freeSSHd 2.1.3 is vulnerable; other versions may also be affected.
Exploit / POC
freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following metasploit is available.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following metasploit is available.
Solution / Fix
freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
freeSSHd Authentication Mechanism Authentication Bypass Vulnerability
References:
References:
- freeSSHd Homepage (freeSSHd)
- FreeSSHD Remote Authentication Bypass Zeroday Exploit (kingcope)