CVE-2003-0047: Medium severity Van Dyke Technologies Securecrt vulnerability
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0047?
CVE-2003-0047 is considered a medium severity vulnerability due to its potential for credential theft.
How do I fix CVE-2003-0047?
To fix CVE-2003-0047, update to the latest versions of SecureCRT 4.1 or later, SecureFX 2.1.3 or later, or Entunnel 1.0.3 or later.
What kind of data is exposed in CVE-2003-0047?
CVE-2003-0047 exposes logon credentials, including plaintext passwords, stored in memory.
Which versions of software are affected by CVE-2003-0047?
CVE-2003-0047 affects SecureCRT 4.0.2 and 3.4.7, SecureFX 2.1.2 and 2.0.4, and Entunnel 1.0.2 and earlier.
Can attackers exploit CVE-2003-0047 remotely?
No, attackers must have access to the system's memory to exploit CVE-2003-0047.