CVE-2004-1541: High severity Van Dyke Technologies Securecrt vulnerability
Published Dec 31, 2004
·Updated
SecureCRT 4.0, 4.1, and possibly other versions, allows remote attackers to execute arbitrary commands via a telnet:// URL that uses the /F option to specify a configuration file on a samba share.
Affected Software
14 affected components
Van Dyke Technologies Securecrt=4.0.1
Van Dyke Technologies Securecrt=4.0.2
Van Dyke Technologies Securecrt=4.0.3
Van Dyke Technologies Securecrt=4.0.4
Van Dyke Technologies Securecrt=4.0.5
Van Dyke Technologies Securecrt=4.1
Van Dyke Technologies Securecrt=4.1.1
Van Dyke Technologies Securecrt=4.1.2
Van Dyke Technologies Securecrt=4.1.3
Van Dyke Technologies Securecrt=4.1.4
Van Dyke Technologies Securecrt=4.1.5
Van Dyke Technologies Securecrt=4.1.6
Van Dyke Technologies Securecrt=4.1.7
Van Dyke Technologies Securecrt=4.1.8
Remediation
Patch Available
Patch Available
Event History
Dec 31, 2004
CVE Published
05:00 AM
Feb 19, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1541?
CVE-2004-1541 is classified as a critical vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2004-1541?
To mitigate CVE-2004-1541, you should upgrade SecureCRT to a version that is not affected by this vulnerability.
3
What versions of SecureCRT are affected by CVE-2004-1541?
Affected versions include SecureCRT 4.0.1 through 4.1.8, with all versions in between also vulnerable.
4
Can CVE-2004-1541 be exploited remotely?
Yes, CVE-2004-1541 can be exploited remotely using crafted telnet URLs.
5
What impact can CVE-2004-1541 have on my system?
Exploitation of CVE-2004-1541 can lead to the execution of arbitrary commands on the affected system.