CVE Vulnerabilities

CVE-1999-1029

Published: May 13, 1999 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

SSH server (sshd2) before 2.0.12 does not properly record login attempts if the connection is closed before the maximum number of tries, allowing a remote attacker to guess the password without showing up in the audit logs.

Affected Software

NameVendorStart VersionEnd Version
Ssh2Ssh2.0 (including)2.0 (including)
Ssh2Ssh2.0.1 (including)2.0.1 (including)
Ssh2Ssh2.0.2 (including)2.0.2 (including)
Ssh2Ssh2.0.3 (including)2.0.3 (including)
Ssh2Ssh2.0.4 (including)2.0.4 (including)
Ssh2Ssh2.0.5 (including)2.0.5 (including)
Ssh2Ssh2.0.6 (including)2.0.6 (including)
Ssh2Ssh2.0.7 (including)2.0.7 (including)
Ssh2Ssh2.0.8 (including)2.0.8 (including)
Ssh2Ssh2.0.9 (including)2.0.9 (including)
Ssh2Ssh2.0.10 (including)2.0.10 (including)
Ssh2Ssh2.0.11 (including)2.0.11 (including)

References