Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2001-1473

33
FAUCET Score

CVE-2001-1473 describes a man-in-the-middle vulnerability in the SSH-1 protocol, affecting SSH implementations. An attacker can create a Session ID matching a target server's, but with a weaker public key, allowing them to compute the corresponding private key and impersonate the target. This vulnerability carries a high severity CVSS score of 7.5, indicating a network-based attack with low complexity and potential for partial compromise of confidentiality, integrity, and availability. Despite its age and high FAUCET Risk Score, there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, though Nuclei templates exist for detecting the deprecated SSHv1 protocol. Community discussion and media coverage are minimal, typical for older CVEs.

Impacted Technologies

VendorProductVersion(s)CPE
1.2.24CPE matchmatch criteria
cpe:2.3:a:ssh:ssh:1.2.24:*:*:*:*:*:*:*
1.2.25CPE matchmatch criteria
cpe:2.3:a:ssh:ssh:1.2.25:*:*:*:*:*:*:*
1.2.26CPE matchmatch criteria
cpe:2.3:a:ssh:ssh:1.2.26:*:*:*:*:*:*:*
1.2.27CPE matchmatch criteria
cpe:2.3:a:ssh:ssh:1.2.27:*:*:*:*:*:*:*
1.2.28CPE matchmatch criteria
cpe:2.3:a:ssh:ssh:1.2.28:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
6.27%
Probability of exploitation in next 30 days
EPSS Percentile
92.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2001-1473 · Apr 23, 2021
This CVE's current EPSS score of 0.0627 is in the 88th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

openldappatch availablevia llm_extracted
Fixed in: 3.0.2
View patch

Vendor Advisories (2)

openldapllm-openldap-b6ab1d0ebc0dc47d

Environment variable passing vulnerability with UseLogin enabled.

Nov 24, 2001
redhatCVE-2001-1473

CVE-2001-1473

References

exchange.xforce.ibmcloud.com / vulnerabilities/6603
kb.cert.org / vuls/id/684820
US Government Resource