CVE-1999-1085
CVSS 2.0 Score 5.0 of 10 (medium)
Details
Published Jun 12, 1998
Updated: Nov 20, 2024
Summary
CVE-1999-1085 is a cybersecurity vulnerability affecting SSH versions 1.2.25 and 1.2.23, as well as others, when utilized in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes. An attacker can insert arbitrary data into an ongoing SSH data stream by exploiting a known plaintext attack. They accomplish this by calculating a valid CRC-32 checksum for the manipulated packet. This vulnerability, also known as the "SSH insertion attack," allows unauthorized data injection.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- SSH