First published: Mon Dec 31 2001(Updated: )
OpenSSH before 3.0.1 with Kerberos V enabled does not properly authenticate users, which could allow remote attackers to login unchallenged.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OpenSSH | =3.0 | |
OpenSSH | =3.0p1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2001-1507 is considered a critical vulnerability as it allows attackers to bypass authentication and gain unauthorized access.
To fix CVE-2001-1507, upgrade OpenSSH to version 3.0.1 or later to ensure proper user authentication.
CVE-2001-1507 affects OpenSSH versions 3.0 and 3.0p1 with Kerberos V enabled.
CVE-2001-1507 enables remote attackers to log in without any authentication challenge.
CVE-2001-1507 was disclosed in 2001 and addresses significant security flaws in earlier versions of OpenSSH.