Family: Misc. --> Category: infos
SSH Tectia Server SFTP Format String Vulnerability Vulnerability Scan
Vulnerability Scan Summary
Checks for format string vulnerability in SSH Tectia Server SFTP subsystem
Detailed Explanation for this Vulnerability Test
The remote SSH server may be affected by a format string
The remote host is running SSH Tectia Server, a commercial SSH server.
According to its banner, the installed version of this software
contains a format string vulnerability in its sftp subsystem. A
remote, authenticated attacker may be able to execute arbitrary code
on the affected host subject to his rights or crash the server
See also :
As a temporary solution, disable the sftp subsystem as described in
the vendor advisory above. A better solution, though, is to upgrade
to SSH Tectia Server version 4.3.7 or 4.4.2 or later.
Low / CVSS Base Score : 2.3
Click HERE for more information and discussions on this network vulnerability scan.