Unrated severityNVD Advisory· Published Mar 25, 2024· Updated Aug 1, 2024
User authentication bypass in wolfSSH server
CVE-2024-2873
Description
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/wolfSSL/wolfssh/pull/670mitrepatch
- github.com/wolfSSL/wolfssh/pull/671mitrepatch
- www.wolfssl.com/docs/security-vulnerabilities/mitrevendor-advisory
News mentions
0No linked articles in our index yet.