VDB
CVE-2003-0786
CVE-2003-0786
PUBLISHED
CVSS 10 CRITICAL
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
EPSS 3.14% · 87.1th percentile
Risk Scores
CVSS 2.0
10
EPSS Score
3.14%
87.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| openbsd | openssh | 3.7.1, 3.7.1p1 |
Timeline
- Sep 25, 2003 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Feb 13, 2024 EPSS Score
References
- http://www.openssh.com/txt/sshpam.adv url
- 8677 vdb
- 20030923 Multiple PAM vulnerabilities in portable OpenSSH mailing-list
- 20030923 Portable OpenSSH 3.7.1p2 released mailing-list
- 20030924 [OpenPKG-SA-2003.042] OpenPKG Security Advisory (openssh) mailing-list
- VU#602204 third-party-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2003-0786 advisory