First published: Sat Feb 01 2003(Updated: )
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SecureCRT | =4.0.2 | |
SecureFX | =2.1.2 | |
SecureFX | =2.0.4 | |
VanDyke Technologies Entunnel | <=1.0.2 | |
SecureCRT | =3.4.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-0047 is considered a medium severity vulnerability due to its potential for credential theft.
To fix CVE-2003-0047, update to the latest versions of SecureCRT 4.1 or later, SecureFX 2.1.3 or later, or Entunnel 1.0.3 or later.
CVE-2003-0047 exposes logon credentials, including plaintext passwords, stored in memory.
CVE-2003-0047 affects SecureCRT 4.0.2 and 3.4.7, SecureFX 2.1.2 and 2.0.4, and Entunnel 1.0.2 and earlier.
No, attackers must have access to the system's memory to exploit CVE-2003-0047.