CRITICAL
openssh: J-PAKE authentication bypass
Published Dec 6, 2010
9.8
CRITICALCVSS 3.1
EPSS 4.24%
Description
OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.
Affected products
No data.
OR
- ≤ 5.6
- 1.2
- 1.2.1
- 1.2.2
- 1.2.3
- 1.2.27
- 1.3
- 1.5
- 1.5.7
- 1.5.8
- 2.1
- 2.1.1
- 2.2
- 2.3
- 2.3.1
- 2.5
- 2.5.1
- 2.5.2
- 2.9
- 2.9.9
- 2.9.9p2
- 2.9p1
- 2.9p2
- 3.0
- 3.0.1
- 3.0.1p1
- 3.0.2
- 3.0.2p1
- 3.0p1
- 3.1
- 3.1p1
- 3.2
- 3.2.2
- 3.2.2p1
- 3.2.3p1
- 3.3
- 3.3p1
- 3.4
- 3.4p1
- 3.5
- 3.5p1
- 3.6
- 3.6.1
- 3.6.1p1
- 3.6.1p2
- 3.7
- 3.7.1
- 3.7.1p1
- 3.7.1p2
- 3.8
- 3.8.1
- 3.8.1p1
- 3.9
- 3.9.1
- 3.9.1p1
- 4.0
- 4.0p1
- 4.1
- 4.1p1
- 4.2
- 4.2p1
- 4.3
- 4.3p1
- 4.3p2
- 4.4
- 4.4p1
- 4.5
- 4.6
- 4.7
- 4.7p1
- 4.8
- 4.9
- 5.0
- 5.1
- 5.2
- 5.3
- 5.4
- 5.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Red Hat statement
Not vulnerable. This issue did not affect the versions of openssh as shipped with Red Hat Enterprise Linux 4, 5, or 6.
Weaknesses (2)
References (11)
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 x_refsource_CONFIRM
- http://seb.dbzteam.org/crypto/jpake-session-key-retrieval.pdf x_refsource_MISCExploit
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/jpake.c#rev1.5 x_refsource_CONFIRMPatch
- http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/jpake.c.diff?r1=1.4%3Br2=1.5%3Bf=h x_refsource_CONFIRM
- https://access.redhat.com/security/cve/CVE-2010-4478 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=659297 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=660642 Issue Tracking
- https://github.com/seb-m/jpake x_refsource_MISC
- https://nvd.nist.gov/vuln/detail/CVE-2010-4478
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12338 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2010-4478
| Link | Providers | Tags |
|---|---|---|
| http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10673 | x_refsource_CONFIRM | |
| http://seb.dbzteam.org/crypto/jpake-session-key-retrieval.pdf | x_refsource_MISCExploit | |
| http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/jpake.c#rev1.5 | x_refsource_CONFIRMPatch | |
| http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/jpake.c.diff?r1=1.4%3Br2=1.5%3Bf=h | x_refsource_CONFIRM | |
| https://access.redhat.com/security/cve/CVE-2010-4478 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=659297 | x_refsource_CONFIRMPatch | |
| https://bugzilla.redhat.com/show_bug.cgi?id=660642 | Issue Tracking | |
| https://github.com/seb-m/jpake | x_refsource_MISC | |
| https://nvd.nist.gov/vuln/detail/CVE-2010-4478 | ||
| https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12338 | vdb-entrysignaturex_refsource_OVAL | |
| https://www.cve.org/CVERecord?id=CVE-2010-4478 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 6, 2010
Updated May 28, 2026
Reserved Dec 6, 2010
Link CVE-2010-4478
CISA Vulnrichment
Updated May 28, 2026