The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target
Published Apr 21, 2005
7.5
HIGHCVSS 2.0
EPSS 6.27%
Description
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the version of the openssh as shipped with Red Hat Enterprise Linux 4. The Red Hat Security Response Team has rated this issue as having low security impact. This issue is not currently planned to be addressed in future openssh updates for Red Hat Enterprise Linux 4. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 5 and 6, since it is SSH-1 protocol specific and those versions did not enable SSH-1 protocol support in the default configuration.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (36 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.27% (0.06268) | 93.36th | v5 (v2026.06.15) |
| Jun 15, 2026 | 6.27% (0.06268) | 92.65th | v5 (v2026.06.15) |
| Apr 1, 2026 | 4.73% (0.04731) | 89.36th | v4 (v2025.03.14) |
| Mar 19, 2026 | 5.86% (0.05858) | 90.45th | v4 (v2025.03.14) |
| Feb 1, 2026 | 4.24% (0.04237) | 88.55th | v4 (v2025.03.14) |
| Jan 10, 2026 | 5.86% (0.05858) | 90.27th | v4 (v2025.03.14) |
| Dec 4, 2025 | 4.73% (0.04731) | 88.98th | v4 (v2025.03.14) |
| Dec 1, 2025 | 3.41% (0.03406) | 87.06th | v4 (v2025.03.14) |
| Nov 4, 2025 | 4.93% (0.04934) | 89.13th | v4 (v2025.03.14) |
| Nov 1, 2025 | 3.45% (0.03446) | 87.05th | v4 (v2025.03.14) |
| Oct 4, 2025 | 4.88% (0.04878) | 89.10th | v4 (v2025.03.14) |
| Oct 1, 2025 | 3.41% (0.03406) | 87.00th | v4 (v2025.03.14) |
| Sep 26, 2025 | 6.38% (0.06384) | 90.65th | v4 (v2025.03.14) |
| Sep 4, 2025 | 4.93% (0.04934) | 89.23th | v4 (v2025.03.14) |
| Sep 1, 2025 | 3.45% (0.03446) | 87.13th | v4 (v2025.03.14) |
| Aug 4, 2025 | 4.93% (0.04934) | 89.23th | v4 (v2025.03.14) |
| Aug 1, 2025 | 3.45% (0.03446) | 87.15th | v4 (v2025.03.14) |
| Jul 25, 2025 | 5.37% (0.05368) | 89.64th | v4 (v2025.03.14) |
| Jul 4, 2025 | 4.27% (0.04272) | 88.34th | v4 (v2025.03.14) |
| Jul 1, 2025 | 2.97% (0.02975) | 85.98th | v4 (v2025.03.14) |
| Jun 4, 2025 | 4.27% (0.04272) | 88.26th | v4 (v2025.03.14) |
| Jun 1, 2025 | 2.97% (0.02975) | 85.91th | v4 (v2025.03.14) |
| May 26, 2025 | 4.27% (0.04272) | 88.24th | v4 (v2025.03.14) |
| May 20, 2025 | 5.59% (0.05594) | 89.80th | v4 (v2025.03.14) |
| May 11, 2025 | 3.35% (0.03351) | 86.63th | v4 (v2025.03.14) |
| Mar 17, 2025 | 2.35% (0.02348) | 83.78th | v4 (v2025.03.14) |
| Dec 15, 2024 | 0.26% (0.00258) | 66.04th | v3 (v2023.03.01) |
| Nov 14, 2024 | 1.79% (0.01792) | 88.52th | v3 (v2023.03.01) |
| Nov 6, 2024 | 0.26% (0.00258) | 65.96th | v3 (v2023.03.01) |
| Oct 3, 2024 | 1.79% (0.01792) | 88.37th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.26% (0.00258) | 64.55th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.26% (0.00258) | 61.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Sep 10, 2022 | 0.89% (0.00885) | 26.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
References (5)
- http://www.kb.cert.org/vuls/id/684820 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- https://access.redhat.com/security/cve/CVE-2001-1473 Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6603 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2001-1473
- https://www.cve.org/CVERecord?id=CVE-2001-1473
| Link | Providers | Tags |
|---|---|---|
| http://www.kb.cert.org/vuls/id/684820 | third-party-advisoryx_refsource_CERT-VNUS Government Resource | |
| https://access.redhat.com/security/cve/CVE-2001-1473 | Vendor Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/6603 | vdb-entryx_refsource_XF | |
| https://nvd.nist.gov/vuln/detail/CVE-2001-1473 | ||
| https://www.cve.org/CVERecord?id=CVE-2001-1473 |
Change history (0)
No recorded changes yet.