Rssh

Vendor:

First CVE: Oct 23, 2004 · Active for 21 years

7
Total CVEs
More Total CVEs than 83% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Rssh over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2004
21 years ago
Most Recent CVE
Feb 6, 2019
2,725 days ago

CVE Severity & Scoring

Rssh7 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown4 (57.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (42.9%)
High0 (0.0%)
Unknown4 (57.1%)
User Interaction
None3 (42.9%)
Unknown4 (57.1%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None2 (28.6%)
Unknown4 (57.1%)

Top CVEs

Signals from CVEs in this product scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Insufficient sanitization of environment variables passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync
Feb 6, 20199.832NONO
Insufficient sanitization of arguments passed to rsync can bypass the restrictions imposed by rssh, a restricted shell that should restrict users to perform only rsync operations,
Feb 6, 20199.832NONO
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Lo
Feb 4, 20197.826NONO
Format string vulnerability in log.c in rssh before 2.2.2 allows remote authenticated users to execute arbitrary code.
Oct 23, 20049.026NONO
Incomplete blacklist vulnerability in rssh before 2.3.4, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via the --rsh command lin
Jan 11, 20134.417NONO
rssh 2.3.2, as used by Debian, Fedora, and others, when the rsync protocol is enabled, allows local users to bypass intended restricted shell access via a (1) "-e" or (2) "--" comm
Jan 11, 20134.417NONO
rssh 2.3.3 and earlier allows local users to bypass intended restricted shell access via crafted environment variables in the command line.
Aug 31, 20122.115NONO

Exploit Exposure

Signals from CVEs in this product scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (7 CVEs).

Media Mentions

Signals from CVEs in this product scope (7 CVEs).

Top CNAs Publishing CVEs For Rssh

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.3.439.13.8%00
2.3.224.40.4%00
2.3.123.30.4%00
2.3.023.30.4%00
2.2.323.30.4%00
2.2.223.30.4%00
2.2.123.30.4%00
2.1.123.30.4%00
2.1.023.30.4%00
2.0.423.30.4%00
2.0.323.30.4%00
2.0.223.30.4%00
2.0.123.30.4%00
2.0.023.30.4%00