CVE-2024-47857

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts to which the "account B" has access.
Configurations

No configuration.

History

18 Mar 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-20

18 Feb 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : unknown
CWE CWE-863

03 Feb 2025, 17:15

Type Values Removed Values Added
Summary
  • (es) SSH Communication Security PrivX las versiones entre 18.0 y 36.0 implementan una validación insuficiente en las firmas de clave pública cuando se utilizan conexiones SSH nativas a través de un puerto proxy. Esto permite que una "cuenta A" de PrivX existente se haga pasar por otra "cuenta B" de PrivX existente y obtenga acceso a los hosts de destino SSH a los que la "cuenta B" tiene acceso.
CWE CWE-863
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

31 Jan 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-31 17:15

Updated : 2025-03-18 20:15


NVD link : CVE-2024-47857

Mitre link : CVE-2024-47857

CVE.ORG link : CVE-2024-47857


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation