VDB

CVE-1999-1085

CVE-1999-1085 PUBLISHED CVSS 5 MEDIUM

SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack."

EPSS 3.16% · 87.2th percentile

Risk Scores

CVSS 2.0
5
EPSS Score
3.16%
87.2th percentile

Affected Products

VendorProductVersions
sshsecure_shell1.2.23, 1.2.25
n/an/an/a

Timeline

  • Jun 12, 1998 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 24, 2023 EPSS Score
  • Jul 16, 2023 EPSS Score
  • Sep 6, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›