CVE-2003-0786

CVSS 10.0 - HIGH
Description

The SSH1 PAM challenge response authentication in OpenSSH 3.7.1 and 3.7.1p1, when Privilege Separation is disabled, does not check the result of the authentication attempt, which can allow remote attackers to gain privileges.

Affected Products
2
Vendor Product Version
openbsd openssh 3.7.1
openbsd openssh 3.7.1p1
Weakness Types
NVD-CWE-Other
CVE Information
CVE ID:
CVE-2003-0786
Published:
2003-11-17
Modified:
2026-04-16
CVSS Score:
10.0
Severity:
HIGH
Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C
Affected Vendors
openbsd
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL