CVE-2010-4478
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
- Openbsd Openssh
- ≤ 5.6, 1.2, 1.2.1, 1.2.2, 1.2.3, 1.2.27, 1.3, 1.5, 1.5.7, 1.5.8, 2.1, 2.1.1, 2.2, 2.3, 2.3.1, 2.5, 2.5.1, 2.5.2, 2.9, 2.9.9, 2.9.9p2, 2.9p1, 2.9p2, 3.0, 3.0.1, 3.0.1p1, 3.0.2, 3.0.2p1, 3.0p1, 3.1, 3.1p1, 3.2, 3.2.2, 3.2.2p1, 3.2.3p1, 3.3, 3.3p1, 3.4, 3.4p1, 3.5
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 4.2% (90th percentile)
- Weakness
- CWE-287
- NVD status
- Modified
- Published
- 2010-12-06
CVE-2010-4478 at NVD
No indexed exploits for CVE-2010-4478 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2010-4478 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.