CVE-2001-1473 describes a man-in-the-middle vulnerability in the SSH-1 protocol, affecting SSH implementations. An attacker can create a Session ID matching a target server's, but with a weaker public key, allowing them to compute the corresponding private key and impersonate the target. This vulnerability carries a high severity CVSS score of 7.5, indicating a network-based attack with low complexity and potential for partial compromise of confidentiality, integrity, and availability. Despite its age and high FAUCET Risk Score, there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, though Nuclei templates exist for detecting the deprecated SSHv1 protocol. Community discussion and media coverage are minimal, typical for older CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.24CPE matchmatch criteria | cpe:2.3:a:ssh:ssh:1.2.24:*:*:*:*:*:*:* | ||
1.2.25CPE matchmatch criteria | cpe:2.3:a:ssh:ssh:1.2.25:*:*:*:*:*:*:* | ||
1.2.26CPE matchmatch criteria | cpe:2.3:a:ssh:ssh:1.2.26:*:*:*:*:*:*:* | ||
1.2.27CPE matchmatch criteria | cpe:2.3:a:ssh:ssh:1.2.27:*:*:*:*:*:*:* | ||
1.2.28CPE matchmatch criteria | cpe:2.3:a:ssh:ssh:1.2.28:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.