Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-6580
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
/n software IPWorks SSH insufficient file access verification
Source: NVD (National Vulnerability Database)
Vulnerability Description
The /n software IPWorks SSH library SFTPServer component can be induced to make unintended filesystem or network path requests when loading a SSH public key or certificate. To be exploitable, an application calling the SFTPServer component must grant user access without verifying the SSH public key or certificate (which would most likely be a separate vulnerability in the calling application). IPWorks SSH versions 22.0.8945 and 24.0.8945 were released to address this condition by blocking all filesystem and network path requests for SSH public keys or certificates.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-1390
Source: NVD (National Vulnerability Database)
Vulnerability Title
IPWorks SSH 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
IPWorks SSH是nsoftware 的一个集成了SSH(Secure Shell)安全功能的库,它允许开发者轻松地将SSH安全集成到互联网应用程序中。 IPWorks SSH存在安全漏洞,该漏洞源于在加载SSH公钥或证书时可能会被诱导发出非预期的文件系统或网络路径请求。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
/n softwareIPWorks SSH SFTPServer 0 ~ 22.0.8945 -
II. Public POCs for CVE-2024-6580
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-6580
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2024-6580

No comments yet


Leave a comment