CVE-2024-6580
Last modified
CVE-2024-6580 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nsoftware | Ipworks Ssh | 22.0.8945 |
| Nsoftware | Ipworks Ssh | 24.0.8945 |
References
- https://www.nsoftware.com/kb/articles/cve-2024-5806Vendor Advisory
- https://www.nsoftware.com/kb/articles/cve-2024-5806Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-6580?
How severe is CVE-2024-6580?
How do I fix CVE-2024-6580?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-6574The Laposta plugin for WordPress is vulnerable to Full Path …5.3
- CVE-2024-6575The The Plus Addons for Elementor – Elementor Addons, Page T…5.4
- CVE-2024-6576Improper Authentication vulnerability in Progress MOVEit Tra…9.8
- CVE-2024-6577In the latest version of pytorch/serve, the script 'upload_r…6.3
- CVE-2024-6578A stored cross-site scripting (XSS) vulnerability exists in …5.4
- CVE-2024-6579The Web and WooCommerce Addons for WPBakery Builder plugin f…4.3
- CVE-2024-6581A vulnerability in the discussion image upload function of t…9
- CVE-2024-6582A broken access control vulnerability exists in the latest v…4.3
- CVE-2024-6583A path traversal vulnerability exists in the latest version …4.3
- CVE-2024-6584The 'wp_ajax_boost_proxy_ig' action allows administrators to…9.1
- CVE-2024-6585Multiple stored cross-site scripting (“XSS”) vulnerabilities…5.4
- CVE-2024-6586Lightdash version 0.1024.6 allows users with the necessary p…7.3
Are you affected by CVE-2024-6580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
