CVE-2022-29245
Summary
| CVE | CVE-2022-29245 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-31 17:15:00 UTC |
| Updated | 2023-11-07 03:45:00 UTC |
| Description | SSH.NET is a Secure Shell (SSH) library for .NET. In versions 2020.0.0 and 2020.0.1, during an `X25519` key exchange, the client’s private key is generated with `System.Random`. `System.Random` is not a cryptographically secure random number generator, it must therefore not be used for cryptographic purposes. When establishing an SSH connection to a remote host, during the X25519 key exchange, the private key is generated with a weak random number generator whose seed can be brute forced. This allows an attacker who is able to eavesdrop on the communications to decrypt them. Version 2020.0.2 contains a patch for this issue. As a workaround, one may disable support for `curve25519-sha256` and `[email protected]` key exchange algorithms. |
Risk And Classification
Problem Types: CWE-338
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ssh.net Project | Ssh.net | 2020.0.0 | - | All | All |
| Application | Ssh.net Project | Ssh.net | 2020.0.0 | beta1 | All | All |
| Application | Ssh.net Project | Ssh.net | 2020.0.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Weak private key generation · Advisory · sshnet/SSH.NET · GitHub | CONFIRM | github.com | |
| Release 2020.0.2 · sshnet/SSH.NET · GitHub | MISC | github.com | |
| Use cryptographically secure random number generator. · sshnet/SSH.NET@03c6d60 · GitHub | MISC | github.com | |
| SSH.NET/KeyExchangeECCurve25519.cs at bc99ada7da3f05f50d9379f2644941d91d5bf05a · sshnet/SSH.NET · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.