CVE Vulnerabilities

CVE-2008-5124

Improper Authentication

Published: Nov 18, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

JSCAPE Secure FTP Applet 4.8.0 and earlier does not ask the user to verify a new or mismatched SSH host key, which makes it easier for remote attackers to perform man-in-the-middle attacks.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Secure_ftp_appletJscape*4.8.0 (including)
Secure_ftp_appletJscape1.1 (including)1.1 (including)
Secure_ftp_appletJscape1.2 (including)1.2 (including)
Secure_ftp_appletJscape1.3 (including)1.3 (including)
Secure_ftp_appletJscape1.4 (including)1.4 (including)
Secure_ftp_appletJscape1.5 (including)1.5 (including)
Secure_ftp_appletJscape1.6 (including)1.6 (including)
Secure_ftp_appletJscape2.0 (including)2.0 (including)
Secure_ftp_appletJscape2.1 (including)2.1 (including)
Secure_ftp_appletJscape2.5 (including)2.5 (including)
Secure_ftp_appletJscape2.6 (including)2.6 (including)
Secure_ftp_appletJscape3.0 (including)3.0 (including)
Secure_ftp_appletJscape3.0.1 (including)3.0.1 (including)
Secure_ftp_appletJscape3.0.2 (including)3.0.2 (including)
Secure_ftp_appletJscape3.0.3 (including)3.0.3 (including)
Secure_ftp_appletJscape3.0.4 (including)3.0.4 (including)
Secure_ftp_appletJscape4.0 (including)4.0 (including)
Secure_ftp_appletJscape4.2.0 (including)4.2.0 (including)
Secure_ftp_appletJscape4.3.0 (including)4.3.0 (including)
Secure_ftp_appletJscape4.4.0 (including)4.4.0 (including)
Secure_ftp_appletJscape4.5.0 (including)4.5.0 (including)
Secure_ftp_appletJscape4.6.0 (including)4.6.0 (including)
Secure_ftp_appletJscape4.7 (including)4.7 (including)

Potential Mitigations

References