Remote Information Disclosure Vulnerability in Eugeny Tabby Product
CVE-2024-48460

4.3MEDIUM

Key Information:

Vendor

Eugeny

Status
Vendor
CVE Published:
16 January 2025

What is CVE-2024-48460?

An identified vulnerability in Eugeny Tabby version 1.0.213 allows attackers to remotely acquire sensitive information. This vulnerability facilitates the unauthorized transmission of SSH usernames and passwords even in cases where host key verification fails. Consequently, affected users may find their credentials compromised, posing a significant security risk.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.