Rssh
Vendor:
First CVE: Oct 23, 2004 · Active for 21 years
7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Rssh over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2004
21 years ago
Most Recent CVE
Feb 6, 2019
2,725 days ago
CVE Severity & Scoring
Rssh7 CVEs
14%
29%
29%
29%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3464CRITICAL Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync | Feb 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-3463CRITICAL Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations, | Feb 6, 2019 | 9.8 | 32 | NO | NO |
CVE-2019-1000018HIGH rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Lo | Feb 4, 2019 | 7.8 | 26 | NO | NO |
CVE-2004-1628HIGH Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code. | Oct 23, 2004 | 9.0 | 26 | NO | NO |
CVE-2012-2252MEDIUM Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command lin | Jan 11, 2013 | 4.4 | 17 | NO | NO |
CVE-2012-2251MEDIUM rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" comm | Jan 11, 2013 | 4.4 | 17 | NO | NO |
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line. | Aug 31, 2012 | 2.1 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Rssh
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.3.4 | 3 | 9.1 | 3.8% | 0 | 0 |
| 2.3.2 | 2 | 4.4 | 0.4% | 0 | 0 |
| 2.3.1 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.3.0 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.2.3 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.2.2 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.2.1 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.1.1 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.1.0 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.0.4 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.0.3 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.0.2 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.0.1 | 2 | 3.3 | 0.4% | 0 | 0 |
| 2.0.0 | 2 | 3.3 | 0.4% | 0 | 0 |