S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2001-1473 Scanner

CVE-2001-1473 scanner - Man in the Middle (MitM) vulnerability in SSH protocol

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
20
Vulnerabilities Found
confirmed findings
References
CVECVE-2001-1473
7.5
CVSS

The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

SSH (Secure Shell) is a protocol used for secure remote login and file transfer between computers over an unsecured network. It is commonly used in the administration of server infrastructure and network devices. SSH provides a secure and encrypted channel for communication between the client and server, ensuring that sensitive data such as login credentials are protected from eavesdropping and tampering.

However, a design flaw in the SSH-1 protocol, known as CVE-2001-1473, was identified that allowed an attacker to execute a man-in-the-middle attack. The flaw occurs when a malicious server establishes two concurrent sessions with the same session ID, allowing the attacker to intercept and modify sensitive information being transmitted between the client and server.

When exploited, the vulnerability can lead to a range of damaging consequences, including the unauthorized disclosure of sensitive data, unauthorized access to critical infrastructure, and loss of business-critical information. Attackers could potentially obtain user privileges on other hosts running an SSH-1 server, resulting in widespread damage.

At s4e.io, we empower individuals and organizations to stay ahead of cyber threats by providing pro-level security features that enable quick identification and remediation of vulnerabilities in digital assets. With our platform, anyone can easily and quickly learn about vulnerabilities in their digital assets, helping them to protect against potential attacks and safeguard their sensitive data. Don't wait until it's too late – visit s4e.io today to learn how we can help you secure your digital assets.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users can take the following precautions:

  • Upgrade to SSH-2, which is not vulnerable to this attack.
  • Be cautious when accepting unknown server keys for SSH connections.
  • Clients should not attempt to start an SSH-1 connection with encryption disabled.
  • Servers should refuse SSH-1 connection requests that have encryption disabled.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.