peter bassill · operator
$ cve CVE-2004-1161 JSON

CVE-2004-1161 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 7.3% (pctl 94)

Patch early

A public exploit exists.

Description

rssh 2.2.2 and earlier does not properly restrict programs that can be run, which could allow remote authenticated users to bypass intended access restrictions and execute arbitrary programs via (1) rdist -P, (2) rsync, or (3) scp -S.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS7.33% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2005-01-10
Last modified2026-06-16

Affected (2)

VendorProduct
gentoolinux
rsshrssh

Public exploits

SourceTitleDate
exploit-dbRSSH 2.x - Arbitrary Command Execution2004-12-02

References

→ the Explorer  ·  watch your stack  ·  NVD