CVE-2012-5975: Critical severity ssh tectia server vulnerability
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-style password authentication is enabled, allows remote attackers to bypass authentication via a crafted session involving entry of blank passwords, as demonstrated by a root login session from a modified OpenSSH client with an added inputuserauthpasswdchangereq call in sshconnect2.c.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-5975?
CVE-2012-5975 has a medium severity rating, indicating potential issues with authentication bypass.
How do I fix CVE-2012-5975?
To fix CVE-2012-5975, update your SSH Tectia Server to a version later than 6.3.2 where the vulnerability is patched.
What systems are affected by CVE-2012-5975?
CVE-2012-5975 affects SSH Tectia Server versions 6.0.4 to 6.3.2 on UNIX and Linux systems.
Can CVE-2012-5975 be exploited remotely?
Yes, CVE-2012-5975 allows remote attackers to bypass authentication under specific conditions.
Is old-style password authentication a risk with CVE-2012-5975?
Yes, the vulnerability is particularly concerning when old-style password authentication is enabled.