CVE-2004-1653 describes a vulnerability in OpenSSH's default configuration where AllowTcpForwarding is enabled, potentially allowing remote authenticated users to perform a port bounce, especially when integrated with anonymous access programs like AnonCVS. With a CVSS score of 6.4, this vulnerability has a network attack vector and low attack complexity, leading to potential partial confidentiality and integrity impacts. Despite its age, recent media coverage indicates attackers are leveraging this decade-old flaw to target IoT devices, transforming them into proxies for malicious traffic, though no public exploit code or Metasploit modules are readily available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.9CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.