Vulnerability Name: | CVE-1999-1085 (CCN-1126) | ||||||||
Assigned: | 1998-06-11 | ||||||||
Published: | 1998-06-11 | ||||||||
Updated: | 2016-10-18 | ||||||||
Summary: | SSH 1.2.25, 1.2.23, and other versions, when used in in CBC (Cipher Block Chaining) or CFB (Cipher Feedback 64 bits) modes, allows remote attackers to insert arbitrary data into an existing stream between an SSH client and server by using a known plaintext attack and computing a valid CRC-32 checksum for the packet, aka the "SSH insertion attack." | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri, 3 Jul 1998 20:09:35 -0300 UPDATE: SSH insertion attack Source: MITRE Type: CNA CVE-1999-1085 Source: BUGTRAQ Type: UNKNOWN 19980612 CORE-SDI-04: SSH insertion attack Source: BUGTRAQ Type: UNKNOWN 19980703 UPDATE: SSH insertion attack Source: CCN Type: CERT Advisory CA-2001-35 Recent Activity Against Secure Shell Daemons Source: CCN Type: Cisco Systems Inc. Security Advisory, 2001 June 27 08:00 (UTC -0800) Multiple SSH Vulnerabilities Source: CCN Type: F-Secure Web site SSH Source: CCN Type: IBM Security Bulletin 2005718 (API Connect) API Connect is affected by SSH vulnerability (CVE-1999-1085) Source: XF Type: UNKNOWN ssh-insert(1126) Source: CCN Type: US-CERT VU#13877 Weak CRC allows packet injection into SSH sessions encrypted with block ciphers Source: CERT-VN Type: US Government Resource VU#13877 Source: CCN Type: OSVDB ID: 212 Multiple Vendor SSH CBC/CFB Data Stream Injection Source: CCN Type: SSH Communications Security Web site Download Source: CCN Type: CORE SDI S.A. Security Advisory SSH Insertion Attack Source: XF Type: UNKNOWN ssh-insert(1126) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |