vendor:
SSH Daemon
by:
hypoclear
7.5
CVSS
HIGH
Input Validation Error
20
CWE
Product Name: SSH Daemon
Affected Version From: 3.0.0
Affected Version To: 3.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:ssh:ssh:3.0.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2002
SSH Short Password Login Vulnerability
It may be possible for remote users to log in to accounts for which there are two or less characters in the password field of the system password file. Due to the nature of the problem, it may be possible to log in to a vulnerable system using such an account with any password. This may lead to further system compromise.
Mitigation:
Ensure that all passwords are of sufficient length and complexity.