← Back to browse · API

CVE-2010-4478

Severity
CRITICAL
CVSS
9.8
EPSS
0.04242
Risk score
40.68
CISA KEV
No
PoC
No
Published
2010-12-06
Modified
2026-05-28
First seen
2026-08-07
Aliases
EUVD-2010-4446, GHSA-7M62-4JFR-67WH
Products
n/a:n/a n/a
Sources
euvd EUVD-2010-4446

Description

OpenSSH 5.6 and earlier, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol, a related issue to CVE-2010-4252.

References