CVE-2012-6066

HIGH

Description

freeSSHd.exe in freeSSHd through 1.2.6 allows remote attackers to bypass authentication via a crafted session, as demonstrated by an OpenSSH client with modified versions of ssh.c and sshconnect2.c.

References

http://archives.neohapsis.com/archives/fulldisclosure/2012-12/0012.html

Details

Source: MITRE

Published: 2012-12-04

Updated: 2012-12-05

Type: CWE-287

Risk Information

CVSS v2.0

Base Score: 9.3

Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 8.6

Severity: HIGH