CVE-2008-5161
Summary
| CVE | CVE-2008-5161 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-11-19 17:30:00 UTC |
| Updated | 2026-05-28 19:16:22 UTC |
| Description | Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors. |
Risk And Classification
Primary CVSS: v3.1 3.7 LOW from ADP
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.018540000 probability, percentile 0.833580000 (date 2026-06-02)
Problem Types: CWE-200 | CWE-329 | n/a | CWE-329 CWE-329 Generation of Predictable IV with CBC Mode
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 3.7 | LOW | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 2.0 | [email protected] | Primary | 2.6 | AV:N/AC:H/Au:N/C:P/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
LowIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:H/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Openbsd | Openssh | 4.7p1 | All | All | All |
| Application | Ssh | Tectia Client | 4.0 | All | All | All |
| Application | Ssh | Tectia Client | 4.0.1 | All | All | All |
| Application | Ssh | Tectia Client | 4.0.3 | All | All | All |
| Application | Ssh | Tectia Client | 4.0.4 | All | All | All |
| Application | Ssh | Tectia Client | 4.0.5 | All | All | All |
| Application | Ssh | Tectia Client | 4.2 | All | All | All |
| Application | Ssh | Tectia Client | 4.2.1 | All | All | All |
| Application | Ssh | Tectia Client | 4.3 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.1 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.1j | All | All | All |
| Application | Ssh | Tectia Client | 4.3.2 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.2j | All | All | All |
| Application | Ssh | Tectia Client | 4.3.3 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.4 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.5 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.6 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.7 | All | All | All |
| Application | Ssh | Tectia Client | 4.3.8k | All | All | All |
| Application | Ssh | Tectia Client | 4.3.9k | All | All | All |
| Application | Ssh | Tectia Client | 4.4 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.1 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.10 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.11 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.2 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.3 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.4 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.6 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.7 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.8 | All | All | All |
| Application | Ssh | Tectia Client | 4.4.9 | All | All | All |
| Application | Ssh | Tectia Client | 5.0.0 | All | All | All |
| Application | Ssh | Tectia Client | 5.0.0f | All | All | All |
| Application | Ssh | Tectia Client | 5.0.1 | All | All | All |
| Application | Ssh | Tectia Client | 5.0.1f | All | All | All |
| Application | Ssh | Tectia Client | 5.0.2 | All | All | All |
| Application | Ssh | Tectia Client | 5.0.2f | All | All | All |
| Application | Ssh | Tectia Client | 5.0.3 | All | All | All |
| Application | Ssh | Tectia Client | 5.0.3f | All | All | All |
| Application | Ssh | Tectia Client | 5.1.0 | All | All | All |
| Application | Ssh | Tectia Client | 5.1.1 | All | All | All |
| Application | Ssh | Tectia Client | 5.1.2 | All | All | All |
| Application | Ssh | Tectia Client | 5.1.3 | All | All | All |
| Application | Ssh | Tectia Client | 5.2.0 | All | All | All |
| Application | Ssh | Tectia Client | 5.2.1 | All | All | All |
| Application | Ssh | Tectia Client | 5.2.2 | All | All | All |
| Application | Ssh | Tectia Client | 5.2.3 | All | All | All |
| Application | Ssh | Tectia Client | 5.2.4 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.0 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.1 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.2 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.3 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.5 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.6 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.7 | All | All | All |
| Application | Ssh | Tectia Client | 5.3.8 | All | All | All |
| Application | Ssh | Tectia Client | 6.0.0 | All | All | All |
| Application | Ssh | Tectia Client | 6.0.1 | All | All | All |
| Application | Ssh | Tectia Client | 6.0.2 | All | All | All |
| Application | Ssh | Tectia Client | 6.0.3 | All | All | All |
| Application | Ssh | Tectia Client | 6.0.4 | All | All | All |
| Application | Ssh | Tectia Connector | 4.0.7 | All | All | All |
| Application | Ssh | Tectia Connector | 4.1.2 | All | All | All |
| Application | Ssh | Tectia Connector | 4.1.3 | All | All | All |
| Application | Ssh | Tectia Connector | 4.1.5 | All | All | All |
| Application | Ssh | Tectia Connector | 4.2.0 | All | All | All |
| Application | Ssh | Tectia Connector | 4.3.0 | All | All | All |
| Application | Ssh | Tectia Connector | 4.3.4 | All | All | All |
| Application | Ssh | Tectia Connector | 4.3.5 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.0 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.10 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.2 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.4 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.6 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.7 | All | All | All |
| Application | Ssh | Tectia Connector | 4.4.9 | All | All | All |
| Application | Ssh | Tectia Connector | 5.0.0 | All | All | All |
| Application | Ssh | Tectia Connector | 5.0.1 | All | All | All |
| Application | Ssh | Tectia Connector | 5.0.2 | All | All | All |
| Application | Ssh | Tectia Connector | 5.0.3 | All | All | All |
| Application | Ssh | Tectia Connector | 5.1.0 | All | All | All |
| Application | Ssh | Tectia Connector | 5.1.1 | All | All | All |
| Application | Ssh | Tectia Connector | 5.1.2 | All | All | All |
| Application | Ssh | Tectia Connector | 5.1.3 | All | All | All |
| Application | Ssh | Tectia Connector | 5.2.2 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.0 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.1 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.2 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.3 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.7 | All | All | All |
| Application | Ssh | Tectia Connector | 5.3.8 | All | All | All |
| Application | Ssh | Tectia Connectsecure | 6.0.0 | All | All | All |
| Application | Ssh | Tectia Connectsecure | 6.0.1 | All | All | All |
| Application | Ssh | Tectia Connectsecure | 6.0.2 | All | All | All |
| Application | Ssh | Tectia Connectsecure | 6.0.3 | All | All | All |
| Application | Ssh | Tectia Connectsecure | 6.0.4 | All | All | All |
| Application | Ssh | Tectia Server | 4.0 | All | All | All |
| Application | Ssh | Tectia Server | 4.0.3 | All | All | All |
| Application | Ssh | Tectia Server | 4.0.4 | All | All | All |
| Application | Ssh | Tectia Server | 4.0.5 | All | All | All |
| Application | Ssh | Tectia Server | 4.0.7 | All | All | All |
| Application | Ssh | Tectia Server | 4.1.2 | All | All | All |
| Application | Ssh | Tectia Server | 4.1.3 | All | All | All |
| Application | Ssh | Tectia Server | 4.1.5 | All | All | All |
| Application | Ssh | Tectia Server | 4.2.0 | All | All | All |
| Application | Ssh | Tectia Server | 4.2.1 | All | All | All |
| Application | Ssh | Tectia Server | 4.2.2 | All | All | All |
| Application | Ssh | Tectia Server | 4.3 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.0 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.1 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.2 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.3 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.4 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.5 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.6 | All | All | All |
| Application | Ssh | Tectia Server | 4.3.7 | All | All | All |
| Application | Ssh | Tectia Server | 4.4 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.0 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.1 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.10 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.11 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.2 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.4 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.5 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.6 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.7 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.8 | All | All | All |
| Application | Ssh | Tectia Server | 4.4.9 | All | All | All |
| Application | Ssh | Tectia Server | 5.0.0 | All | All | All |
| Application | Ssh | Tectia Server | 5.0.1 | All | All | All |
| Application | Ssh | Tectia Server | 5.0.2 | All | All | All |
| Application | Ssh | Tectia Server | 5.0.3 | All | All | All |
| Application | Ssh | Tectia Server | 5.1.0 | All | All | All |
| Application | Ssh | Tectia Server | 5.1.1 | All | All | All |
| Application | Ssh | Tectia Server | 5.1.1 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.1.2 | All | All | All |
| Application | Ssh | Tectia Server | 5.1.3 | All | All | All |
| Application | Ssh | Tectia Server | 5.2.0 | All | All | All |
| Application | Ssh | Tectia Server | 5.2.0 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.2.1 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.2.2 | All | All | All |
| Application | Ssh | Tectia Server | 5.2.2 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.2.3 | All | All | All |
| Application | Ssh | Tectia Server | 5.2.4 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.0 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.0 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.3.1 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.2 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.3 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.4 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.5 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.6 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.7 | All | All | All |
| Application | Ssh | Tectia Server | 5.3.8 | All | All | All |
| Application | Ssh | Tectia Server | 5.4.0 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.4.1 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.4.2 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.5.0 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 5.5.1 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 6.0.0 | All | All | All |
| Application | Ssh | Tectia Server | 6.0.0 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 6.0.1 | All | All | All |
| Application | Ssh | Tectia Server | 6.0.1 | All | ibm_zos | All |
| Application | Ssh | Tectia Server | 6.0.2 | All | All | All |
| Application | Ssh | Tectia Server | 6.0.3 | All | All | All |
| Application | Ssh | Tectia Server | 6.0.4 | All | All | All |
| Application | Ssh | Tectia Server | 6.0.4 | All | linux_ibm_zos | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Repository / Oval Repository | af854a3a-2127-422b-91ae-364da2661108 | oval.cisecurity.org | |
| osvdb.org/50036 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| SecurityTracker.com Archives - OpenSSH CBC Mode Error Handling May Let Certain Remote Users Obtain Plain Text in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SANS Internet Storm Center; Cooperative Network Security Community - Internet Security - isc | af854a3a-2127-422b-91ae-364da2661108 | isc.sans.org | |
| Attachmate Products SSH CBC Mode Plaintext Recovery Vulnerability - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SSH Tectia Products CBC Mode Plaintext Recovery Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| osvdb.org/50035 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| OpenSSH CBC Mode Plaintext Recovery Vulnerability - Secunia Advisories - Vulnerability Information - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| 403 Forbidden | af854a3a-2127-422b-91ae-364da2661108 | www.cpni.gov.uk | |
| support.attachmate.com/techdocs/2398.html | af854a3a-2127-422b-91ae-364da2661108 | support.attachmate.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Sun Solaris SSH CBC Mode Plaintext Recovery Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Red Hat update for openssh - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| SSH - Company - News | af854a3a-2127-422b-91ae-364da2661108 | www.ssh.com | Vendor Advisory |
| '[security bulletin] HPSBMA02447 SSRT090062 rev.1 - Insight Control Suite For Linux (ICE-LX) Cross Si' - MARC | af854a3a-2127-422b-91ae-364da2661108 | marc.info | |
| McAfee KnowledgeBase - McAfee Security Bulletin - Data Loss Prevention hotfix resolves two security issues | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| Avaya CMS Solaris SSH CBC Mode Plaintext Recovery Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| FAQ for YAMAHA RT Series / Security | af854a3a-2127-422b-91ae-364da2661108 | www.rtpro.yamaha.co.jp | |
| sunsolve.sun.com/search/document.do | af854a3a-2127-422b-91ae-364da2661108 | sunsolve.sun.com | |
| About Security Update 2009-006 / Mac OS X v10.6.2 | af854a3a-2127-422b-91ae-364da2661108 | support.apple.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| OpenSSH CBC Mode Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| US-CERT Vulnerability Note VU#958563 | af854a3a-2127-422b-91ae-364da2661108 | www.kb.cert.org | US Government Resource |
| SecurityTracker.com Archives - Solaris Secure Shell CBC Mode Error Handling May Let Certain Remote Users Obtain Plain Text in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| McAfee Security Bulletin: Network Data Loss Prevention update fixes CVE-2015-2808 and CVE-2008-5161 | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | |
| APPLE-SA-2009-11-09-1 Security Update 2009-006 / Mac OS X v10.6.2 | af854a3a-2127-422b-91ae-364da2661108 | lists.apple.com | |
| SecurityTracker.com Archives - SSH Tectia CBC Mode Error Handling May Let Certain Remote Users Obtain Plain Text in Certain Cases | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| HPE Support document - HPE Support Center | af854a3a-2127-422b-91ae-364da2661108 | h20566.www2.hpe.com | |
| rhn.redhat.com | Red Hat Support | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Juniper Networks - 2015-10 Security Bulletin: CTPView: Multiple Vulnerabilities in CTPView | af854a3a-2127-422b-91ae-364da2661108 | kb.juniper.net | |
| openssh.org/txt/cbc.adv | af854a3a-2127-422b-91ae-364da2661108 | openssh.org | |
| Yamaha RT Series Routers SSH CBC Mode Plaintext Recovery - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| ASA-2008-503 (SUN 247186) | af854a3a-2127-422b-91ae-364da2661108 | support.avaya.com | |
| osvdb.org/49872 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2009-09-02 | Joshua Bressers | This issue was addressed for Red Hat Enterprise Linux 5 by https://rhn.redhat.com/errata/RHSA-2009-1287.html After reviewing the upstream fix for this issue, Red Hat does not intend to address this flaw in Red Hat Enterprise Linux 3 or 4 at this time. |
There are currently no legacy QID mappings associated with this CVE.