Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

SSH < 3.0.1 Locked Account Remote Authentication Bypass

Medium

Synopsis

The remote host is vulnerable to a flaw which allows for the bypassing of authentication.

Description

The remote host is running SSH 3.0.0. There is a vulnerability in this release which allows any user to log into accounts that have passwords of two characters long or less. An attacker may gain root privileges using this flaw.

Solution

Upgrade to SSH 3.0.1 or higher.