CVE-2004-1653: Medium severity OpenBSD OpenSSH vulnerability
The default configuration for OpenSSH enables AllowTcpForwarding, which could allow remote authenticated users to perform a port bounce, when configured with an anonymous access program such as AnonCVS.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1653?
CVE-2004-1653 is considered a moderate severity vulnerability due to its potential for unauthorized access via TCP forwarding.
How do I fix CVE-2004-1653?
To fix CVE-2004-1653, disable AllowTcpForwarding in the OpenSSH configuration file.
Who is affected by CVE-2004-1653?
CVE-2004-1653 affects users of OpenSSH versions up to 3.9 with default configuration settings.
What might an attacker gain by exploiting CVE-2004-1653?
An attacker exploiting CVE-2004-1653 could perform a port bounce attack, potentially gaining access to unauthorized services.
Is there a patch available for CVE-2004-1653?
There is no dedicated patch for CVE-2004-1653, but users should upgrade to a later version of OpenSSH that addresses this vulnerability.