SSH before 2.0, when using RC4 and password authentication, allows remote attackers to replay messages until a new server key (VK) is generated.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/6490 | vdb entry |
http://www.kb.cert.org/vuls/id/665372 | us government resource third party advisory patch |