CVE-2024-2873: User authentication bypass in wolfSSH server
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wolfSSHto a version that resolves this vulnerability.Fixed in 1.4.17
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2873?
The severity of CVE-2024-2873 is considered high due to the potential for unauthorized access by malicious clients.
How do I fix CVE-2024-2873?
To fix CVE-2024-2873, upgrade wolfSSH to version 1.4.17 or later.
What types of systems are affected by CVE-2024-2873?
CVE-2024-2873 affects server-side implementations of wolfSSH prior to version 1.4.17.
What impact does CVE-2024-2873 have on security?
CVE-2024-2873 can lead to unauthorized channel creation, which compromises server security.
Is CVE-2024-2873 an authenticated or unauthenticated vulnerability?
CVE-2024-2873 is an unauthenticated vulnerability allowing access without prior user authentication.