CVE-2003-0786
CVSS 10.0 - HIGH
Description
The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.
Affected Products
2| Vendor | Product | Version |
|---|---|---|
| openbsd | openssh |
3.7.1
|
| openbsd | openssh |
3.7.1p1
|
References
Weakness Types
NVD-CWE-Other
CVE Information
- CVE ID:
CVE-2003-0786- Published:
- 2003-11-17
- Modified:
- 2026-04-16
- CVSS Score:
- 10.0
- Severity:
- HIGH
- Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Vendors
openbsd
Quick Actions
CVSS Severity Scale
0.0 - 3.9
LOW
4.0 - 6.9
MEDIUM
7.0 - 8.9
HIGH
9.0 - 10.0
CRITICAL