Lucene search

K
cve[email protected]CVE-2001-0144
HistoryMay 07, 2001 - 4:00 a.m.

CVE-2001-0144

2001-05-0704:00:00
web.nvd.nist.gov
48
cve-2001-0144
core sdi ssh1
crc-32 compensation attack
remote attacks
integer overflow

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

High

0.122 Low

EPSS

Percentile

95.4%

CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.

Affected configurations

NVD
Node
openbsdopensshMatch1.2.2
OR
openbsdopensshMatch1.2.3
OR
openbsdopensshMatch2.1
OR
openbsdopensshMatch2.1.1
OR
openbsdopensshMatch2.2
OR
sshsshMatch1.2.24
OR
sshsshMatch1.2.25
OR
sshsshMatch1.2.26
OR
sshsshMatch1.2.27
OR
sshsshMatch1.2.28
OR
sshsshMatch1.2.29
OR
sshsshMatch1.2.30
OR
sshsshMatch1.2.31

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.4 High

AI Score

Confidence

High

0.122 Low

EPSS

Percentile

95.4%