Back

CRITICAL

User authentication bypass in wolfSSH server

Published Mar 25, 2024

Description

A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.

Affected products

Remediation

Vendor solution

The fix for this issue is located in the following GitHub Pull Requests: * https://github.com/wolfSSL/wolfssh/pull/670

* https://github.com/wolfSSL/wolfssh/pull/671

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner wolfSSL
Published Mar 25, 2024
Updated Aug 1, 2024
Reserved Mar 25, 2024
CISA Vulnrichment
Updated Aug 1, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner wolfSSL
Published Mar 25, 2024
Updated Aug 1, 2024
Exploited since n/a
EUVD-2024-27817