Lucene search

K
nvd[email protected]NVD:CVE-2008-1657
HistoryApr 02, 2008 - 6:44 p.m.

CVE-2008-1657

2008-04-0218:44:00
CWE-264
web.nvd.nist.gov
2

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.2%

OpenSSH 4.4 up to versions before 4.9 allows remote authenticated users to bypass the sshd_config ForceCommand directive by modifying the .ssh/rc session file.

Affected configurations

NVD
Node
openbsdopensshMatch4.4
OR
openbsdopensshMatch4.4p1
OR
openbsdopensshMatch4.5
OR
openbsdopensshMatch4.6
OR
openbsdopensshMatch4.7
OR
openbsdopensshMatch4.8

References

6.5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

6.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

75.2%