VDB
CVE-2001-0144
CVE-2001-0144
PUBLISHED
CVSS 10 CRITICAL
CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow.
EPSS 53.31% · 98.0th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
53.31%
98.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| ssh | ssh | 1.2.24, 1.2.25, 1.2.26 |
| n/a | n/a | n/a |
| openbsd | openssh | 1.2.2, 1.2.3, 2.1 |
Timeline
- CVE Published
- Feb 8, 2001 PoC Published
- Sep 23, 2010 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Mar 7, 2023 EPSS Score
- May 8, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- 2347 vdb
- ssh-deattack-overwrite-memory(6083) vdb
- 503 vdb
- 20010208 [CORE SDI ADVISORY] SSH1 CRC-32 compensation attack detector mailing-list
- 795 vdb
- 20010208 Remote vulnerability in SSH daemon crc32 compensation attack detector vendor-advisory
- CA-2001-35 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2001-0144 advisory