SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts to which the "account B" has access.
This Cyber News was published on www.tenable.com. Publication date: Sat, 01 Feb 2025 05:01:02 +0000