search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Icon Labs SSH server vulnerabilities

Vulnerability Note VU#626979

Original Release Date: 2008-06-09 | Last Revised: 2009-04-23

Overview

The Icon Labs Iconfidant SSH server contails multiple vulnerabilities. The most severe of these issues may allow an attacker to cause a vulnerable system to crash.

Description

The Iconfident SSH is a Secure Shell (SSH) server that runs on VxWorks-based systems. Versions of the Iconfident server prior to 2.3.8 contain multiple denial of service vulnerabilities.

Impact

A remote, unauthenticated attacker may be able to cause a vulnerable system to crash or become unable to accept remote SSH connections.

Solution

Upgrade

Icon Labs has released Iconfident SSH server 2.3.8 to address these issues.


Restrict access

Restricting access to the Iconfident SSH server by using access control lists or firewall rules may prevent an attacker from exploiting this vulnerability.

Vendor Information

626979
 

View all 57 vendors View less vendors


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Icon Labs for information that was used in this report.

This document was written by Ryan Giobbi.

Other Information

CVE IDs: None
Severity Metric: 5.63
Date Public: 2008-05-21
Date First Published: 2008-06-09
Date Last Updated: 2009-04-23 11:10 UTC
Document Revision: 13

Sponsored by CISA.