SSH Secure Shell for Servers 3.0.0 to 3.1.1 allows remote attackers to override the AllowedAuthentications configuration and use less secure authentication schemes (e.g. password) than configured for the server.
https://exchange.xforce.ibmcloud.com/vulnerabilities/9163
http://www.ssh.com/products/ssh/advisories/authentication.cfm
http://www.ssh.com/company/newsroom/article/201/
http://www.securityfocus.com/bid/4810
http://www.kb.cert.org/vuls/id/341187
http://www.ciac.org/ciac/bulletins/m-081.shtml
http://archives.neohapsis.com/archives/bugtraq/2002-05/0204.html