// For flags

CVE-2006-5484

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SSH Tectia Client/Server/Connector 5.1.0 and earlier, Manager 2.2.0 and earlier, and other products, when using an RSA key with exponent 3, removes PKCS-1 padding before generating a hash, which allows remote attackers to forge a PKCS #1 v1.5 signature that is signed by that RSA key and prevents Tectia from correctly verifying X.509 and other certificates that use PKCS #1, a similar issue to CVE-2006-4339.

SSH Tectia Client/Server/Connector 5.1.0 y anteriores, Manager 2.2.0 y anteriores, y otros productos, al usar una clave RSA con exponente 3, borra el relleno PKCS-1 antes de generar un hash, lo cual permite a atacantes remotos forjar una firma PKCS #1 v1.5 que es firmada por esa clave RSA y evita que Tectia verifique correctamente certificados X.509 y otros certificados que usan PKCS #1, un asunto similar a CVE-2006-4339.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2006-10-24 CVE Reserved
  • 2006-10-24 CVE Published
  • 2023-10-05 EPSS Updated
  • 2024-08-07 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ssh
Search vendor "Ssh"
Tectia Client
Search vendor "Ssh" for product "Tectia Client"
<= 5.1.0
Search vendor "Ssh" for product "Tectia Client" and version " <= 5.1.0"
-
Affected
Ssh
Search vendor "Ssh"
Tectia Connector
Search vendor "Ssh" for product "Tectia Connector"
<= 5.1.0
Search vendor "Ssh" for product "Tectia Connector" and version " <= 5.1.0"
-
Affected
Ssh
Search vendor "Ssh"
Tectia Manager
Search vendor "Ssh" for product "Tectia Manager"
<= 2.2.0
Search vendor "Ssh" for product "Tectia Manager" and version " <= 2.2.0"
-
Affected
Ssh
Search vendor "Ssh"
Tectia Server
Search vendor "Ssh" for product "Tectia Server"
<= 5.1.0
Search vendor "Ssh" for product "Tectia Server" and version " <= 5.1.0"
-
Affected