CVE-1999-1010
CVSS 2.0 Score 2.1 of 10 (low)
Details
Published Dec 14, 1999
Updated: Nov 20, 2024
Summary
CVE-1999-1010 is a vulnerability affecting SSH 1.2.27 servers. Despite server policies disallowing it, clients can still use the "none" cipher during connections. This cipher offers no encryption, leaving data transmitted between the client and server vulnerable to interception and decryption by unauthorized parties. This issue poses a significant risk for sensitive information, as it can be easily read or modified during transmission. To mitigate this vulnerability, it is recommended that affected servers be updated to a more secure version of SSH.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OpenSSH
Affected Vendors
- OpenBSD Project