CVE-2024-47857: Input Validation
SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts to which the "account B" has access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47857?
CVE-2024-47857 is classified as a critical vulnerability due to its potential to allow account impersonation and unauthorized access.
How do I fix CVE-2024-47857?
To fix CVE-2024-47857, it is recommended to upgrade SSH Communications Security PrivX to a version higher than 36.0.
What versions are affected by CVE-2024-47857?
CVE-2024-47857 affects SSH Communications Security PrivX versions between 18.0 and 36.0.
What systems are at risk with CVE-2024-47857?
Systems using SSH Communications Security PrivX as their SSH access management solution are at risk due to CVE-2024-47857.
Can CVE-2024-47857 lead to data breaches?
Yes, CVE-2024-47857 can lead to data breaches by enabling unauthorized users to impersonate legitimate accounts and access sensitive systems.