CVE-2004-1161
HIGH 7.5EPSS 7.3%
rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.
- CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 7.33% chance of exploitation in the next 30 days, 94th percentile
- Published
- 2004-12-10
- Updated
- 2024-08-08