CRITICAL🇵🇱 Wersja polska

CVE-2010-4478

CVSS 9.8v2.0pub. 2010-12-06upd. 2026-05-28

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Openbsd OpenSSH

    APP
    Openbsd
    1.21.2.11.2.21.2.271.2.31.31.51.5.71.5.82.12.1.12.22.32.3.12.5+ 63 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-38408CRITICAL9.8PL ✓same product

RCE w OpenSSH ssh-agent przez niezaufaną ścieżkę ładowania PKCS#11

CVE-2023-28531CRITICAL9.8PL ✓same product

OpenSSH ssh-add: brak ograniczeń destination constraints dla kluczy smartcard

CVE-2016-1908CRITICAL9.8PL ✓same product

OpenSSH: pominięcie kontroli dostępu w przekierowaniu X11 (Auth Bypass)

CVE-2002-0639CRITICAL9.8PL ✓same product

Integer overflow w OpenSSH umożliwiający zdalne wykonanie kodu (RCE)

CVE-2002-0083CRITICAL9.8PL ✓same product

OpenSSH: błąd off-by-one w kodzie kanałów umożliwia eskalację uprawnień