CVE-2024-6580
CVE-2024-6580
Título es
CVE-2024-6580
Lun, 08/07/2024 – 19:15
Tipo
CWE-1390
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-6580
Descripción en
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.
08/07/2024
08/07/2024
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
Pendiente de análisis
Enviar en el boletín
Off