CVE-2001-1507: High severity OpenBSD OpenSSH vulnerability
Published Dec 31, 2001
·Updated
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
Affected Software
2 affected components
OpenBSD OpenSSH=3.0
OpenBSD OpenSSH=3.0p1
Remediation
Patch Available
Patch Available
Patch Available
Event History
Dec 31, 2001
CVE Published
05:00 AM
Jul 14, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1507?
CVE-2001-1507 is considered a critical vulnerability as it allows attackers to bypass authentication and gain unauthorized access.
2
How do I fix CVE-2001-1507?
To fix CVE-2001-1507, upgrade OpenSSH to version 3.0.1 or later to ensure proper user authentication.
3
What affected versions are associated with CVE-2001-1507?
CVE-2001-1507 affects OpenSSH versions 3.0 and 3.0p1 with Kerberos V enabled.
4
What type of attacks can be executed via CVE-2001-1507?
CVE-2001-1507 enables remote attackers to log in without any authentication challenge.
5
When was CVE-2001-1507 disclosed?
CVE-2001-1507 was disclosed in 2001 and addresses significant security flaws in earlier versions of OpenSSH.