Unrated severityNVD Advisory· Published Feb 19, 2003· Updated Apr 16, 2026
CVE-2003-0047
CVE-2003-0047
Description
SSH2 clients for VanDyke (1) SecureCRT 4.0.2 and 3.4.7, (2) SecureFX 2.1.2 and 2.0.4, and (3) Entunnel 1.0.2 and earlier, do not clear logon credentials from memory, including plaintext passwords, which could allow attackers with access to memory to steal the SSH credentials.
Affected products
5- cpe:2.3:a:van_dyke_technologies:entunnel:*:*:*:*:*:*:*:*Range: <=1.0.2
cpe:2.3:a:van_dyke_technologies:securecrt:3.4.7:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:van_dyke_technologies:securecrt:3.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:van_dyke_technologies:securecrt:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:van_dyke_technologies:securefx:2.0.4:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:van_dyke_technologies:securefx:2.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:van_dyke_technologies:securefx:2.1.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8News mentions
0No linked articles in our index yet.