First published: Tue Dec 14 1999(Updated: )
An SSH 1.2.27 server allows a client to use the "none" cipher, even if it is not allowed by the server policy.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =1.2.27 | |
=1.2.27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1010 is classified as a medium severity vulnerability.
To fix CVE-1999-1010, configure the SSH server to disable the 'none' cipher usage.
CVE-1999-1010 specifically affects OpenSSH version 1.2.27.
The primary risk of CVE-1999-1010 is that it allows for weaker encryption methods, potentially exposing data to interception.
While CVE-1999-1010 is an older vulnerability, it highlights historical weaknesses in SSH implementations that can inform current security practices.