{"api_version":"1","generated_at":"2026-07-16T01:41:37+00:00","cve":"CVE-2023-48795","urls":{"html":"https://cve.report/CVE-2023-48795","api":"https://cve.report/api/cve/CVE-2023-48795.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-48795","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-48795"},"summary":{"title":"CVE-2023-48795","description":"The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.","state":"PUBLISHED","assigner":"mitre","published_at":"2023-12-18 16:15:10","updated_at":"2026-05-12 11:16:15"},"problem_types":["CWE-354","n/a","CWE-354 CWE-354 Improper Validation of Integrity Check Value"],"metrics":[{"version":"3.1","source":"nvd@nist.gov","type":"Primary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"3.1","source":"ADP","type":"DECLARED","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},{"version":"3.1","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","score":"5.9","severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}}],"references":[{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002","name":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Security Advisory","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/mwiede/jsch/pull/461","name":"https://github.com/mwiede/jsch/pull/461","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://bugs.gentoo.org/920280","name":"https://bugs.gentoo.org/920280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-364175.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-364175.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/advisories/GHSA-45x7-px36-x8w8","name":"https://github.com/advisories/GHSA-45x7-px36-x8w8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"http://seclists.org/fulldisclosure/2024/Mar/21","name":"http://seclists.org/fulldisclosure/2024/Mar/21","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/","name":"https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2023/12/20/3","name":"http://www.openwall.com/lists/oss-security/2023/12/20/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Mitigation"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html","name":"https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.debian.org/security/2023/dsa-5586","name":"https://www.debian.org/security/2023/dsa-5586","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"Debian -- Security Information -- DSA-5586-1 openssh","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/hierynomus/sshj/issues/916","name":"https://github.com/hierynomus/sshj/issues/916","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC","name":"https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://gitlab.com/libssh/libssh-mirror/-/tags","name":"https://gitlab.com/libssh/libssh-mirror/-/tags","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://forum.netgate.com/topic/184941/terrapin-ssh-attack","name":"https://forum.netgate.com/topic/184941/terrapin-ssh-attack","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.theregister.com/2023/12/20/terrapin_attack_ssh","name":"https://www.theregister.com/2023/12/20/terrapin_attack_ssh","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.bitvise.com/ssh-server-version-history","name":"https://www.bitvise.com/ssh-server-version-history","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://nova.app/releases/#v11.8","name":"https://nova.app/releases/#v11.8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/TeraTermProject/teraterm/releases/tag/v5.1","name":"https://github.com/TeraTermProject/teraterm/releases/tag/v5.1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html","name":"https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22","name":"https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/rapier1/hpn-ssh/releases","name":"https://github.com/rapier1/hpn-ssh/releases","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://oryx-embedded.com/download/#changelog","name":"https://oryx-embedded.com/download/#changelog","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html","name":"https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mwiede/jsch/issues/457","name":"https://github.com/mwiede/jsch/issues/457","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES","name":"https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://news.ycombinator.com/item?id=38732005","name":"https://news.ycombinator.com/item?id=38732005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"403"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/drakkan/sftpgo/releases/tag/v2.5.6","name":"https://github.com/drakkan/sftpgo/releases/tag/v2.5.6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2023/12/18/2","name":"https://www.openwall.com/lists/oss-security/2023/12/18/2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://crates.io/crates/thrussh/versions","name":"https://crates.io/crates/thrussh/versions","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"inode/x-empty","httpstatus":"404","archivestatus":"200"},{"url":"https://security-tracker.debian.org/tracker/source-package/trilead-ssh2","name":"https://security-tracker.debian.org/tracker/source-package/trilead-ssh2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html","name":"https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 3718-1] php-phpseclib security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2023/12/19/5","name":"http://www.openwall.com/lists/oss-security/2023/12/19/5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html","name":"https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"[SECURITY] [DLA 3694-1] openssh security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 39 Update: podman-4.8.3-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/NixOS/nixpkgs/pull/275249","name":"https://github.com/NixOS/nixpkgs/pull/275249","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ssh-mitm/ssh-mitm/issues/165","name":"https://github.com/ssh-mitm/ssh-mitm/issues/165","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://winscp.net/eng/docs/history#6.2.2","name":"https://winscp.net/eng/docs/history#6.2.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst","name":"https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://news.ycombinator.com/item?id=38684904","name":"https://news.ycombinator.com/item?id=38684904","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"403"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 39 Update: prometheus-podman-exporter-1.7.0-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg","name":"https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 39 Update: putty-0.80-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.vandyke.com/products/securecrt/history.txt","name":"https://www.vandyke.com/products/securecrt/history.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/erlang/otp/releases/tag/OTP-26.2.1","name":"https://github.com/erlang/otp/releases/tag/OTP-26.2.1","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: putty-0.80-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab","name":"https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: libssh-0.10.6-2.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.debian.org/security/2023/dsa-5588","name":"https://www.debian.org/security/2023/dsa-5588","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"Debian -- Security Information -- DSA-5588-1 putty","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: prometheus-podman-exporter-1.7.0-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/","name":"https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://matt.ucc.asn.au/dropbear/CHANGES","name":"https://matt.ucc.asn.au/dropbear/CHANGES","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/janmojzis/tinyssh/issues/81","name":"https://github.com/janmojzis/tinyssh/issues/81","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0","name":"https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15","name":"https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openssh.com/openbsd.html","name":"https://www.openssh.com/openbsd.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202312-16","name":"https://security.gentoo.org/glsa/202312-16","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-915275.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-915275.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://help.panic.com/releasenotes/transmit5/","name":"https://help.panic.com/releasenotes/transmit5/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/proftpd/proftpd/issues/456","name":"https://github.com/proftpd/proftpd/issues/456","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update","name":"https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security-tracker.debian.org/tracker/CVE-2023-48795","name":"https://security-tracker.debian.org/tracker/CVE-2023-48795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.bitvise.com/ssh-client-version-history#933","name":"https://www.bitvise.com/ssh-client-version-history#933","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://security.gentoo.org/glsa/202312-17","name":"https://security.gentoo.org/glsa/202312-17","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: golang-x-crypto-0.18.0-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/apache/mina-sshd/issues/445","name":"https://github.com/apache/mina-sshd/issues/445","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html","name":"http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2254210","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2254210","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.netsarang.com/en/xshell-update-history/","name":"https://www.netsarang.com/en/xshell-update-history/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/security/cve/cve-2023-48795","name":"https://access.redhat.com/security/cve/cve-2023-48795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25","name":"https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability","name":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/warp-tech/russh/releases/tag/v0.40.2","name":"https://github.com/warp-tech/russh/releases/tag/v0.40.2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html","name":"https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508","name":"https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/","name":"https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3","name":"https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1217950","name":"https://bugzilla.suse.com/show_bug.cgi?id=1217950","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://ubuntu.com/security/CVE-2023-48795","name":"https://ubuntu.com/security/CVE-2023-48795","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/libssh2/libssh2/pull/1291","name":"https://github.com/libssh2/libssh2/pull/1291","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES","name":"https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/paramiko/paramiko/issues/2337","name":"https://github.com/paramiko/paramiko/issues/2337","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-794697.html","name":"https://cert-portal.siemens.com/productcert/html/ssa-794697.html","refsource":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6","name":"https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://thorntech.com/cve-2023-48795-and-sftp-gateway/","name":"https://thorntech.com/cve-2023-48795-and-sftp-gateway/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: golang-x-mod-0.14.0-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/cyd01/KiTTY/issues/520","name":"https://github.com/cyd01/KiTTY/issues/520","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html","name":"https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42","name":"https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta","name":"https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://security-tracker.debian.org/tracker/source-package/libssh2","name":"https://security-tracker.debian.org/tracker/source-package/libssh2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2024/03/06/3","name":"http://www.openwall.com/lists/oss-security/2024/03/06/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2024/04/17/8","name":"http://www.openwall.com/lists/oss-security/2024/04/17/8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.paramiko.org/changelog.html","name":"https://www.paramiko.org/changelog.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html","name":"https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] [DLA 3719-1] phpseclib security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2023/12/18/3","name":"http://www.openwall.com/lists/oss-security/2023/12/18/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 39 Update: golang-x-mod-0.14.0-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/ronf/asyncssh/tags","name":"https://github.com/ronf/asyncssh/tags","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://twitter.com/TrueSkrillor/status/1736774389725565005","name":"https://twitter.com/TrueSkrillor/status/1736774389725565005","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Press/Media Coverage"],"title":"","mime":"","httpstatus":"400","archivestatus":"200"},{"url":"https://www.terrapin-attack.com","name":"https://www.terrapin-attack.com","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://filezilla-project.org/versions.php","name":"https://filezilla-project.org/versions.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"403","archivestatus":"200"},{"url":"https://www.openssh.com/txt/release-9.6","name":"https://www.openssh.com/txt/release-9.6","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://news.ycombinator.com/item?id=38685286","name":"https://news.ycombinator.com/item?id=38685286","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"403"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security.netapp.com/advisory/ntap-20240105-0004/","name":"https://security.netapp.com/advisory/ntap-20240105-0004/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 39 Update: golang-x-crypto-0.18.0-1.fc39 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/","name":"https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"403","archivestatus":"200"},{"url":"https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5","name":"https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://roumenpetrov.info/secsh/#news20231220","name":"https://roumenpetrov.info/secsh/#news20231220","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/openssh/openssh-portable/commits/master","name":"https://github.com/openssh/openssh-portable/commits/master","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d","name":"https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/","name":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16","name":"https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ","name":"https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES","name":"https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: python-paramiko-3.4.0-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 38 Update: podman-4.8.3-1.fc38 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit","name":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://github.com/PowerShell/Win32-OpenSSH/issues/2189","name":"https://github.com/PowerShell/Win32-OpenSSH/issues/2189","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/","name":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2023/12/20/3","name":"https://www.openwall.com/lists/oss-security/2023/12/20/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Mitigation"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://support.apple.com/kb/HT214084","name":"https://support.apple.com/kb/HT214084","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg","name":"https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc","name":"https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Release Notes"],"title":"","mime":"","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-48795","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-48795","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"RUGGEDCOM APE1808","version":"affected * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.5 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.5 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","version":"affected V3.1.5 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","version":"affected V3.1.5 * custom","platforms":[]},{"source":"ADP","vendor":"Siemens","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","version":"affected V3.1.5 * custom","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"48795","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"apple","cpe5":"macos","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"48795","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"filezilla-project","cpe5":"filezilla_client","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"48795","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"openbsd","cpe5":"openssh","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"48795","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"panic","cpe5":"transmit_5","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"48795","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"putty","cpe5":"putty","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2023-48795","qid":"161329","title":"Oracle Enterprise Linux Security Update for libssh (ELSA-2024-0628)"},{"cve":"CVE-2023-48795","qid":"161330","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-0606)"},{"cve":"CVE-2023-48795","qid":"161350","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-12158)"},{"cve":"CVE-2023-48795","qid":"161351","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-12157)"},{"cve":"CVE-2023-48795","qid":"161357","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-12164)"},{"cve":"CVE-2023-48795","qid":"161396","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-1130)"},{"cve":"CVE-2023-48795","qid":"161405","title":"Oracle Enterprise Linux Security Update for buildah (ELSA-2024-1150)"},{"cve":"CVE-2023-48795","qid":"161419","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-12233)"},{"cve":"CVE-2023-48795","qid":"161420","title":"Oracle Enterprise Linux Security Update for openssh (ELSA-2024-12232)"},{"cve":"CVE-2023-48795","qid":"200017","title":"Ubuntu Security Notification for libssh Vulnerability (USN-6561-1)"},{"cve":"CVE-2023-48795","qid":"200018","title":"Ubuntu Security Notification for OpenSSH Vulnerabilities (USN-6560-1)"},{"cve":"CVE-2023-48795","qid":"200041","title":"Ubuntu Security Notification for OpenSSH Vulnerabilities (USN-6560-2)"},{"cve":"CVE-2023-48795","qid":"200046","title":"Ubuntu Security Notification for libssh2 Vulnerability (USN-6585-1)"},{"cve":"CVE-2023-48795","qid":"200057","title":"Ubuntu Security Notification for FileZilla Vulnerability (USN-6589-1)"},{"cve":"CVE-2023-48795","qid":"200069","title":"Ubuntu Security Notification for Paramiko Vulnerability (USN-6598-1)"},{"cve":"CVE-2023-48795","qid":"242764","title":"Red Hat Update for libssh (RHSA-2024:0499)"},{"cve":"CVE-2023-48795","qid":"242766","title":"Red Hat Update for libssh (RHSA-2024:0538)"},{"cve":"CVE-2023-48795","qid":"242805","title":"Red Hat Update for openssh (RHSA-2024:0606)"},{"cve":"CVE-2023-48795","qid":"242811","title":"Red Hat Update for libssh (RHSA-2024:0625)"},{"cve":"CVE-2023-48795","qid":"242814","title":"Red Hat Update for libssh (RHSA-2024:0628)"},{"cve":"CVE-2023-48795","qid":"242828","title":"Red Hat Update for openssh (RHSA-2024:0594)"},{"cve":"CVE-2023-48795","qid":"242841","title":"Red Hat Update for openssh (RHSA-2024:0455)"},{"cve":"CVE-2023-48795","qid":"242848","title":"Red Hat Update for openssh (RHSA-2024:0429)"},{"cve":"CVE-2023-48795","qid":"242989","title":"Red Hat OpenShift Container Platform 4.15 Security Update (RHSA-2023:7201)"},{"cve":"CVE-2023-48795","qid":"243017","title":"Red Hat Update for openssh (RHSA-2024:1130)"},{"cve":"CVE-2023-48795","qid":"243033","title":"Red Hat Update for buildah (RHSA-2024:1150)"},{"cve":"CVE-2023-48795","qid":"243042","title":"Red Hat Update for JBoss Enterprise Application Platform 8.0.1 (RHSA-2024:1193)"},{"cve":"CVE-2023-48795","qid":"243043","title":"Red Hat Update for JBoss Enterprise Application Platform 7.4 (RHSA-2024:1196)"},{"cve":"CVE-2023-48795","qid":"243044","title":"Red Hat Update for JBoss Enterprise Application Platform 8.0.1 (RHSA-2024:1192)"},{"cve":"CVE-2023-48795","qid":"243173","title":"Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:1676)"},{"cve":"CVE-2023-48795","qid":"243174","title":"Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:1675)"},{"cve":"CVE-2023-48795","qid":"243175","title":"Red Hat Update for JBoss Enterprise Application Platform 7.4.1 (RHSA-2024:1674)"},{"cve":"CVE-2023-48795","qid":"284839","title":"Fedora Security Update for podman (FEDORA-2023-cb8c606fbb)"},{"cve":"CVE-2023-48795","qid":"284840","title":"Fedora Security Update for proftpd (FEDORA-2023-b87ec6cf47)"},{"cve":"CVE-2023-48795","qid":"284849","title":"Fedora Security Update for putty (FEDORA-2024-71c2c6526c)"},{"cve":"CVE-2023-48795","qid":"284850","title":"Fedora Security Update for python (FEDORA-2024-39a8c72ea9)"},{"cve":"CVE-2023-48795","qid":"284862","title":"Fedora Security Update for golang (FEDORA-2024-ae653fb07b)"},{"cve":"CVE-2023-48795","qid":"284864","title":"Fedora Security Update for golang (FEDORA-2024-2705241461)"},{"cve":"CVE-2023-48795","qid":"284870","title":"Fedora Security Update for podman (FEDORA-2024-06ebb70bdd)"},{"cve":"CVE-2023-48795","qid":"284889","title":"Fedora Security Update for prometheus (FEDORA-2024-3fd1bc9276)"},{"cve":"CVE-2023-48795","qid":"285023","title":"Fedora Security Update for prometheus (FEDORA-2024-a53b24023d)"},{"cve":"CVE-2023-48795","qid":"285053","title":"Fedora Security Update for golang (FEDORA-2024-fb32950d11)"},{"cve":"CVE-2023-48795","qid":"285055","title":"Fedora Security Update for golang (FEDORA-2024-7b08207cdb)"},{"cve":"CVE-2023-48795","qid":"285066","title":"Fedora Security Update for podman (FEDORA-2024-3bb23c77f3)"},{"cve":"CVE-2023-48795","qid":"285068","title":"Fedora Security Update for putty (FEDORA-2024-d946b9ad25)"},{"cve":"CVE-2023-48795","qid":"285075","title":"Fedora Security Update for python (FEDORA-2023-e77300e4b5)"},{"cve":"CVE-2023-48795","qid":"285076","title":"Fedora Security Update for proftpd (FEDORA-2023-153404713b)"},{"cve":"CVE-2023-48795","qid":"285080","title":"Fedora Security Update for podman (FEDORA-2023-20feb865d8)"},{"cve":"CVE-2023-48795","qid":"285088","title":"Fedora Security Update for libssh (FEDORA-2023-0733306be9)"},{"cve":"CVE-2023-48795","qid":"296108","title":"Oracle Solaris 11.4 Support Repository Update (SRU) 66.164.1 Missing (CPUJAN2024)"},{"cve":"CVE-2023-48795","qid":"330166","title":"IBM Advanced Interactive eXecutive (AIX) Multiple Vulnerabilities (openssh_advisory16)"},{"cve":"CVE-2023-48795","qid":"356793","title":"Amazon Linux Security Advisory for openssh : ALAS2-2023-2376"},{"cve":"CVE-2023-48795","qid":"356794","title":"Amazon Linux Security Advisory for openssh : ALAS2023-2023-462"},{"cve":"CVE-2023-48795","qid":"356795","title":"Amazon Linux Security Advisory for openssh : ALAS-2023-1898"},{"cve":"CVE-2023-48795","qid":"356999","title":"Amazon Linux Security Advisory for openssh : AL2012-2023-483"},{"cve":"CVE-2023-48795","qid":"379295","title":"Putty Terrapin Attack SSH Connection Weakening Vulnerability"},{"cve":"CVE-2023-48795","qid":"379302","title":"Windows Secure Copy (WinSCP) Security Update"},{"cve":"CVE-2023-48795","qid":"379344","title":"Alibaba Cloud Linux Security Update for libssh (ALINUX3-SA-2024:0014)"},{"cve":"CVE-2023-48795","qid":"379366","title":"Fortinet FortiAnalyzer and FortiManager - Improper Access Control Vulnerability (FG-IR-23-490)"},{"cve":"CVE-2023-48795","qid":"379473","title":"Jenkins Plugins Multiple Security Vulnerabilities (Jenkins Security Advisory 2024-03-06)"},{"cve":"CVE-2023-48795","qid":"379478","title":"Apple macOS Sonoma 14.4 Not Installed (HT214084)"},{"cve":"CVE-2023-48795","qid":"38913","title":"SSH Prefix Truncation Vulnerability (Terrapin)"},{"cve":"CVE-2023-48795","qid":"44169","title":"Juniper Network Operating System (Junos OS) Terrapin Attack SSH Connection Weakening Vulnerability (JSA76462)"},{"cve":"CVE-2023-48795","qid":"503807","title":"Alpine Linux Security Update for dropbear"},{"cve":"CVE-2023-48795","qid":"503809","title":"Alpine Linux Security Update for libssh2"},{"cve":"CVE-2023-48795","qid":"503855","title":"Alpine Linux Security Update for proftpd"},{"cve":"CVE-2023-48795","qid":"503904","title":"Alpine Linux Security Update for dropbear"},{"cve":"CVE-2023-48795","qid":"504326","title":"Alpine Linux Security Update for putty"},{"cve":"CVE-2023-48795","qid":"505868","title":"Alpine Linux Security Update for dropbear"},{"cve":"CVE-2023-48795","qid":"505888","title":"Alpine Linux Security Update for libssh2"},{"cve":"CVE-2023-48795","qid":"505902","title":"Alpine Linux Security Update for openssh"},{"cve":"CVE-2023-48795","qid":"505986","title":"Alpine Linux Security Update for buildah"},{"cve":"CVE-2023-48795","qid":"506001","title":"Alpine Linux Security Update for doctl"},{"cve":"CVE-2023-48795","qid":"506043","title":"Alpine Linux Security Update for erlang"},{"cve":"CVE-2023-48795","qid":"506053","title":"Alpine Linux Security Update for filezilla"},{"cve":"CVE-2023-48795","qid":"506076","title":"Alpine Linux Security Update for gitea"},{"cve":"CVE-2023-48795","qid":"506112","title":"Alpine Linux Security Update for libssh"},{"cve":"CVE-2023-48795","qid":"506157","title":"Alpine Linux Security Update for pijul"},{"cve":"CVE-2023-48795","qid":"506158","title":"Alpine Linux Security Update for podman-tui"},{"cve":"CVE-2023-48795","qid":"506161","title":"Alpine Linux Security Update for podman"},{"cve":"CVE-2023-48795","qid":"506169","title":"Alpine Linux Security Update for py3-asyncssh"},{"cve":"CVE-2023-48795","qid":"506178","title":"Alpine Linux Security Update for py3-paramiko"},{"cve":"CVE-2023-48795","qid":"506261","title":"Alpine Linux Security Update for tinyssh"},{"cve":"CVE-2023-48795","qid":"510674","title":"Alpine Linux Security Update for nebula"},{"cve":"CVE-2023-48795","qid":"510681","title":"Alpine Linux Security Update for openssh"},{"cve":"CVE-2023-48795","qid":"510754","title":"Alpine Linux Security Update for openssh"},{"cve":"CVE-2023-48795","qid":"510755","title":"Alpine Linux Security Update for putty"},{"cve":"CVE-2023-48795","qid":"6000398","title":"Debian Security Update for openssh (DSA 5586-1)"},{"cve":"CVE-2023-48795","qid":"6000402","title":"Debian Security Update for putty (DSA 5588-1)"},{"cve":"CVE-2023-48795","qid":"6000403","title":"Debian Security Update for openssh (DLA 3694-1)"},{"cve":"CVE-2023-48795","qid":"6000408","title":"Debian Security Update for libssh (DSA 5591-1)"},{"cve":"CVE-2023-48795","qid":"6000430","title":"Debian Security Update for php-phpseclib3 (DSA 5601-1)"},{"cve":"CVE-2023-48795","qid":"6000431","title":"Debian Security Update for phpseclib (DSA 5599-1)"},{"cve":"CVE-2023-48795","qid":"6000432","title":"Debian Security Update for php-phpseclib (DSA 5600-1)"},{"cve":"CVE-2023-48795","qid":"6000445","title":"Debian Security Update for php-phpseclib (DLA 3718-1)"},{"cve":"CVE-2023-48795","qid":"6000446","title":"Debian Security Update for phpseclib (DLA 3719-1)"},{"cve":"CVE-2023-48795","qid":"6000460","title":"Debian Security Update for python-asyncssh (DLA 3730-1)"},{"cve":"CVE-2023-48795","qid":"673335","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1316)"},{"cve":"CVE-2023-48795","qid":"673339","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1217)"},{"cve":"CVE-2023-48795","qid":"673381","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1338)"},{"cve":"CVE-2023-48795","qid":"673413","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1183)"},{"cve":"CVE-2023-48795","qid":"673430","title":"EulerOS Security Update for proftpd (EulerOS-SA-2024-1323)"},{"cve":"CVE-2023-48795","qid":"673454","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1239)"},{"cve":"CVE-2023-48795","qid":"673471","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1339)"},{"cve":"CVE-2023-48795","qid":"673472","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1197)"},{"cve":"CVE-2023-48795","qid":"673543","title":"EulerOS Security Update for proftpd (EulerOS-SA-2024-1222)"},{"cve":"CVE-2023-48795","qid":"673551","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1317)"},{"cve":"CVE-2023-48795","qid":"673621","title":"EulerOS Security Update for proftpd (EulerOS-SA-2024-1244)"},{"cve":"CVE-2023-48795","qid":"673655","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1203)"},{"cve":"CVE-2023-48795","qid":"673667","title":"EulerOS Security Update for python-paramiko (EulerOS-SA-2024-1224)"},{"cve":"CVE-2023-48795","qid":"673686","title":"EulerOS Security Update for proftpd (EulerOS-SA-2024-1345)"},{"cve":"CVE-2023-48795","qid":"673750","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1216)"},{"cve":"CVE-2023-48795","qid":"673780","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1178)"},{"cve":"CVE-2023-48795","qid":"673785","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1177)"},{"cve":"CVE-2023-48795","qid":"673788","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1321)"},{"cve":"CVE-2023-48795","qid":"673811","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1286)"},{"cve":"CVE-2023-48795","qid":"673872","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1343)"},{"cve":"CVE-2023-48795","qid":"673894","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1241)"},{"cve":"CVE-2023-48795","qid":"673897","title":"EulerOS Security Update for libssh2 (EulerOS-SA-2024-1198)"},{"cve":"CVE-2023-48795","qid":"673937","title":"EulerOS Security Update for openssh (EulerOS-SA-2024-1219)"},{"cve":"CVE-2023-48795","qid":"673955","title":"EulerOS Security Update for python-paramiko (EulerOS-SA-2024-1246)"},{"cve":"CVE-2023-48795","qid":"674082","title":"EulerOS Security Update for libssh (EulerOS-SA-2024-1238)"},{"cve":"CVE-2023-48795","qid":"691379","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for putty (91955195-9ebb-11ee-bc14-a703705db3a6)"},{"cve":"CVE-2023-48795","qid":"691381","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for nebula (0f7598cc-9fe2-11ee-b47f-901b0e9408dc)"},{"cve":"CVE-2023-48795","qid":"691386","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for Free Berkeley Software Distribution (FreeBSD) (13d83980-9f18-11ee-8e38-002590c1f29c)"},{"cve":"CVE-2023-48795","qid":"691404","title":"Free Berkeley Software Distribution (FreeBSD) Security Update for rclone (b5e22ec5-bc4b-11ee-b0b5-b42e991fc52e)"},{"cve":"CVE-2023-48795","qid":"710817","title":"Gentoo Linux libssh Multiple Vulnerabilities (GLSA 202312-16)"},{"cve":"CVE-2023-48795","qid":"710818","title":"Gentoo Linux OpenSSH Multiple Vulnerabilities (GLSA 202312-17)"},{"cve":"CVE-2023-48795","qid":"731307","title":"Palo Alto Networks (PAN-OS)Impact of Terrapin SSH Attack Vulnerability (PAN-241547, CGSDW-19542)"},{"cve":"CVE-2023-48795","qid":"755496","title":"SUSE Enterprise Linux Security Update for openssh (SUSE-SU-2023:4905-1)"},{"cve":"CVE-2023-48795","qid":"755497","title":"SUSE Enterprise Linux Security Update for openssh (SUSE-SU-2023:4904-1)"},{"cve":"CVE-2023-48795","qid":"755498","title":"SUSE Enterprise Linux Security Update for openssh (SUSE-SU-2023:4903-1)"},{"cve":"CVE-2023-48795","qid":"755499","title":"SUSE Enterprise Linux Security Update for openssh (SUSE-SU-2023:4902-1)"},{"cve":"CVE-2023-48795","qid":"755517","title":"SUSE Enterprise Linux Security Update for libssh2_org (SUSE-SU-2023:4946-1)"},{"cve":"CVE-2023-48795","qid":"755553","title":"SUSE Enterprise Linux Security Update for libssh2_org (SUSE-SU-2024:0006-1)"},{"cve":"CVE-2023-48795","qid":"755579","title":"SUSE Enterprise Linux Security Update for python-paramiko (SUSE-SU-2024:0035-1)"},{"cve":"CVE-2023-48795","qid":"755645","title":"SUSE Enterprise Linux Security Update for erlang (SUSE-SU-2024:0210-1)"},{"cve":"CVE-2023-48795","qid":"755655","title":"SUSE Enterprise Linux Security Update for apache-parent, apache-sshd (SUSE-SU-2024:0224-1)"},{"cve":"CVE-2023-48795","qid":"755708","title":"SUSE Enterprise Linux Security Update for bouncycastle, jsch (SUSE-SU-2024:0327-1)"},{"cve":"CVE-2023-48795","qid":"755732","title":"SUSE Enterprise Linux Security Update for cosign (SUSE-SU-2024:0430-1)"},{"cve":"CVE-2023-48795","qid":"755745","title":"SUSE Enterprise Linux Security Update for rekor (SUSE-SU-2024:0460-1)"},{"cve":"CVE-2023-48795","qid":"755791","title":"SUSE Enterprise Linux Security Update for libssh2_org (SUSE-SU-2024:0543-1)"},{"cve":"CVE-2023-48795","qid":"755792","title":"SUSE Enterprise Linux Security Update for libssh2_org (SUSE-SU-2024:0558-1)"},{"cve":"CVE-2023-48795","qid":"755806","title":"SUSE Enterprise Linux Security Update for libssh (SUSE-SU-2024:0539-1)"},{"cve":"CVE-2023-48795","qid":"755989","title":"SUSE Enterprise Linux Security Update for jsch-agent-proxy (SUSE-SU-2024:0974-1)"},{"cve":"CVE-2023-48795","qid":"755991","title":"SUSE Enterprise Linux Security Update for jbcrypt, trilead-ssh2 (SUSE-SU-2024:0972-1)"},{"cve":"CVE-2023-48795","qid":"770234","title":"Red Hat OpenShift Container Platform 4.15 Security Update (RHSA-2023:7201)"},{"cve":"CVE-2023-48795","qid":"907717","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for libssh (32200-1)"},{"cve":"CVE-2023-48795","qid":"907796","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for jsch (32259-2)"},{"cve":"CVE-2023-48795","qid":"907806","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for openssh (32204-1)"},{"cve":"CVE-2023-48795","qid":"907822","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-engine (32280-2)"},{"cve":"CVE-2023-48795","qid":"907868","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for moby-cli (32223-1)"},{"cve":"CVE-2023-48795","qid":"907970","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for erlang (32196-1)"},{"cve":"CVE-2023-48795","qid":"907979","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for libssh2 (32201-1)"},{"cve":"CVE-2023-48795","qid":"907980","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for cert-manager (32195-1)"},{"cve":"CVE-2023-48795","qid":"907991","title":"Common Base Linux Mariner (CBL-Mariner) Security Update for nmap (32202-1)"},{"cve":"CVE-2023-48795","qid":"941560","title":"AlmaLinux Security Update for openssh (ALSA-2024:0606)"},{"cve":"CVE-2023-48795","qid":"941563","title":"AlmaLinux Security Update for libssh (ALSA-2024:0628)"},{"cve":"CVE-2023-48795","qid":"941611","title":"AlmaLinux Security Update for buildah (ALSA-2024:1150)"},{"cve":"CVE-2023-48795","qid":"941612","title":"AlmaLinux Security Update for openssh (ALSA-2024:1130)"},{"cve":"CVE-2023-48795","qid":"961110","title":"Rocky Linux Security Update for openssh (RLSA-2024:0606)"},{"cve":"CVE-2023-48795","qid":"961112","title":"Rocky Linux Security Update for libssh (RLSA-2024:0628)"},{"cve":"CVE-2023-48795","qid":"996349","title":"GO (Go) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)"},{"cve":"CVE-2023-48795","qid":"996375","title":"Rust (Rust) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)"},{"cve":"CVE-2023-48795","qid":"996391","title":"Python (Pip) Security Update for golang.org/x/crypto (GHSA-45x7-px36-x8w8)"}]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2025-11-04T22:05:21.417Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit"},{"url":"https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability"},{"tags":["x_transferred"],"url":"https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html"},{"tags":["x_transferred"],"url":"https://matt.ucc.asn.au/dropbear/CHANGES"},{"tags":["x_transferred"],"url":"https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES"},{"tags":["x_transferred"],"url":"https://www.netsarang.com/en/xshell-update-history/"},{"tags":["x_transferred"],"url":"https://www.paramiko.org/changelog.html"},{"tags":["x_transferred"],"url":"https://www.openssh.com/openbsd.html"},{"tags":["x_transferred"],"url":"https://github.com/openssh/openssh-portable/commits/master"},{"tags":["x_transferred"],"url":"https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ"},{"tags":["x_transferred"],"url":"https://www.bitvise.com/ssh-server-version-history"},{"tags":["x_transferred"],"url":"https://github.com/ronf/asyncssh/tags"},{"tags":["x_transferred"],"url":"https://gitlab.com/libssh/libssh-mirror/-/tags"},{"tags":["x_transferred"],"url":"https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/"},{"tags":["x_transferred"],"url":"https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42"},{"tags":["x_transferred"],"url":"https://www.openssh.com/txt/release-9.6"},{"tags":["x_transferred"],"url":"https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/"},{"tags":["x_transferred"],"url":"https://www.terrapin-attack.com"},{"tags":["x_transferred"],"url":"https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25"},{"tags":["x_transferred"],"url":"https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst"},{"tags":["x_transferred"],"url":"https://thorntech.com/cve-2023-48795-and-sftp-gateway/"},{"tags":["x_transferred"],"url":"https://github.com/warp-tech/russh/releases/tag/v0.40.2"},{"tags":["x_transferred"],"url":"https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0"},{"tags":["x_transferred"],"url":"https://www.openwall.com/lists/oss-security/2023/12/18/2"},{"tags":["x_transferred"],"url":"https://twitter.com/TrueSkrillor/status/1736774389725565005"},{"tags":["x_transferred"],"url":"https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d"},{"tags":["x_transferred"],"url":"https://github.com/paramiko/paramiko/issues/2337"},{"tags":["x_transferred"],"url":"https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg"},{"tags":["x_transferred"],"url":"https://news.ycombinator.com/item?id=38684904"},{"tags":["x_transferred"],"url":"https://news.ycombinator.com/item?id=38685286"},{"name":"[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2023/12/18/3"},{"tags":["x_transferred"],"url":"https://github.com/mwiede/jsch/issues/457"},{"tags":["x_transferred"],"url":"https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6"},{"tags":["x_transferred"],"url":"https://github.com/erlang/otp/releases/tag/OTP-26.2.1"},{"tags":["x_transferred"],"url":"https://github.com/advisories/GHSA-45x7-px36-x8w8"},{"tags":["x_transferred"],"url":"https://security-tracker.debian.org/tracker/source-package/libssh2"},{"tags":["x_transferred"],"url":"https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg"},{"tags":["x_transferred"],"url":"https://security-tracker.debian.org/tracker/CVE-2023-48795"},{"tags":["x_transferred"],"url":"https://bugzilla.suse.com/show_bug.cgi?id=1217950"},{"tags":["x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2254210"},{"tags":["x_transferred"],"url":"https://bugs.gentoo.org/920280"},{"tags":["x_transferred"],"url":"https://ubuntu.com/security/CVE-2023-48795"},{"tags":["x_transferred"],"url":"https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/"},{"tags":["x_transferred"],"url":"https://access.redhat.com/security/cve/cve-2023-48795"},{"tags":["x_transferred"],"url":"https://github.com/mwiede/jsch/pull/461"},{"tags":["x_transferred"],"url":"https://github.com/drakkan/sftpgo/releases/tag/v2.5.6"},{"tags":["x_transferred"],"url":"https://github.com/libssh2/libssh2/pull/1291"},{"tags":["x_transferred"],"url":"https://forum.netgate.com/topic/184941/terrapin-ssh-attack"},{"tags":["x_transferred"],"url":"https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5"},{"tags":["x_transferred"],"url":"https://github.com/rapier1/hpn-ssh/releases"},{"tags":["x_transferred"],"url":"https://github.com/proftpd/proftpd/issues/456"},{"tags":["x_transferred"],"url":"https://github.com/TeraTermProject/teraterm/releases/tag/v5.1"},{"tags":["x_transferred"],"url":"https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15"},{"tags":["x_transferred"],"url":"https://oryx-embedded.com/download/#changelog"},{"tags":["x_transferred"],"url":"https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update"},{"tags":["x_transferred"],"url":"https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22"},{"tags":["x_transferred"],"url":"https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab"},{"tags":["x_transferred"],"url":"https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3"},{"tags":["x_transferred"],"url":"https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC"},{"tags":["x_transferred"],"url":"https://crates.io/crates/thrussh/versions"},{"tags":["x_transferred"],"url":"https://github.com/NixOS/nixpkgs/pull/275249"},{"name":"[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2023/12/19/5"},{"tags":["x_transferred"],"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc"},{"tags":["x_transferred"],"url":"https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/"},{"name":"[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2023/12/20/3"},{"tags":["x_transferred"],"url":"http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html"},{"tags":["x_transferred"],"url":"https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES"},{"tags":["x_transferred"],"url":"https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES"},{"tags":["x_transferred"],"url":"https://github.com/apache/mina-sshd/issues/445"},{"tags":["x_transferred"],"url":"https://github.com/hierynomus/sshj/issues/916"},{"tags":["x_transferred"],"url":"https://github.com/janmojzis/tinyssh/issues/81"},{"tags":["x_transferred"],"url":"https://www.openwall.com/lists/oss-security/2023/12/20/3"},{"tags":["x_transferred"],"url":"https://security-tracker.debian.org/tracker/source-package/trilead-ssh2"},{"tags":["x_transferred"],"url":"https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16"},{"name":"FEDORA-2023-0733306be9","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"},{"name":"DSA-5586","tags":["vendor-advisory","x_transferred"],"url":"https://www.debian.org/security/2023/dsa-5586"},{"tags":["x_transferred"],"url":"https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508"},{"tags":["x_transferred"],"url":"https://www.theregister.com/2023/12/20/terrapin_attack_ssh"},{"tags":["x_transferred"],"url":"https://filezilla-project.org/versions.php"},{"tags":["x_transferred"],"url":"https://nova.app/releases/#v11.8"},{"tags":["x_transferred"],"url":"https://roumenpetrov.info/secsh/#news20231220"},{"tags":["x_transferred"],"url":"https://www.vandyke.com/products/securecrt/history.txt"},{"tags":["x_transferred"],"url":"https://help.panic.com/releasenotes/transmit5/"},{"tags":["x_transferred"],"url":"https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta"},{"tags":["x_transferred"],"url":"https://github.com/PowerShell/Win32-OpenSSH/issues/2189"},{"tags":["x_transferred"],"url":"https://winscp.net/eng/docs/history#6.2.2"},{"tags":["x_transferred"],"url":"https://www.bitvise.com/ssh-client-version-history#933"},{"tags":["x_transferred"],"url":"https://github.com/cyd01/KiTTY/issues/520"},{"name":"DSA-5588","tags":["vendor-advisory","x_transferred"],"url":"https://www.debian.org/security/2023/dsa-5588"},{"tags":["x_transferred"],"url":"https://github.com/ssh-mitm/ssh-mitm/issues/165"},{"tags":["x_transferred"],"url":"https://news.ycombinator.com/item?id=38732005"},{"name":"[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update","tags":["mailing-list","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"},{"name":"GLSA-202312-16","tags":["vendor-advisory","x_transferred"],"url":"https://security.gentoo.org/glsa/202312-16"},{"name":"GLSA-202312-17","tags":["vendor-advisory","x_transferred"],"url":"https://security.gentoo.org/glsa/202312-17"},{"name":"FEDORA-2023-20feb865d8","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"},{"name":"FEDORA-2023-cb8c606fbb","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/"},{"name":"FEDORA-2023-e77300e4b5","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"},{"name":"FEDORA-2023-b87ec6cf47","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/"},{"name":"FEDORA-2023-153404713b","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/"},{"tags":["x_transferred"],"url":"https://security.netapp.com/advisory/ntap-20240105-0004/"},{"name":"FEDORA-2024-3bb23c77f3","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/"},{"name":"FEDORA-2023-55800423a8","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"},{"name":"FEDORA-2024-d946b9ad25","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"},{"name":"FEDORA-2024-71c2c6526c","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/"},{"name":"FEDORA-2024-39a8c72ea9","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"},{"tags":["x_transferred"],"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002"},{"name":"FEDORA-2024-ae653fb07b","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/"},{"name":"FEDORA-2024-2705241461","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"},{"name":"FEDORA-2024-fb32950d11","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/"},{"name":"FEDORA-2024-7b08207cdb","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"},{"name":"FEDORA-2024-06ebb70bdd","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"},{"name":"[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update","tags":["mailing-list","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html"},{"name":"[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update","tags":["mailing-list","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html"},{"name":"FEDORA-2024-a53b24023d","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"},{"name":"FEDORA-2024-3fd1bc9276","tags":["vendor-advisory","x_transferred"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"},{"tags":["x_transferred"],"url":"https://support.apple.com/kb/HT214084"},{"name":"20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4","tags":["mailing-list","x_transferred"],"url":"http://seclists.org/fulldisclosure/2024/Mar/21"},{"name":"[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update","tags":["mailing-list","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"},{"name":"[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2024/04/17/8"},{"name":"[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins","tags":["mailing-list","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2024/03/06/3"},{"url":"https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html"},{"url":"https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html"},{"url":"https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"}],"title":"CVE Program Container"},{"metrics":[{"cvssV3_1":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":5.9,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","version":"3.1"}},{"other":{"content":{"id":"CVE-2023-48795","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2023-12-22T05:01:05.519910Z","version":"2.0.3"},"type":"ssvc"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-354","description":"CWE-354 Improper Validation of Integrity Check Value","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2025-08-27T20:45:57.733Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"affected":[{"defaultStatus":"unknown","product":"RUGGEDCOM APE1808","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.5","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.5","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.5","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.5","versionType":"custom"}]},{"defaultStatus":"unknown","product":"SIPLUS S7-1500 CPU 1518-4 PN/DP MFP","vendor":"Siemens","versions":[{"lessThan":"*","status":"affected","version":"V3.1.5","versionType":"custom"}]}],"providerMetadata":{"dateUpdated":"2026-05-12T11:02:25.905Z","orgId":"0b142b55-0307-4c5a-b3c9-f314f3fb7c5e","shortName":"siemens-SADP"},"references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-794697.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-364175.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-915275.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-769027.html"},{"url":"https://cert-portal.siemens.com/productcert/html/ssa-082556.html"}],"x_adpType":"supplier"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2024-05-01T18:06:23.972Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"url":"https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html"},{"url":"https://matt.ucc.asn.au/dropbear/CHANGES"},{"url":"https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES"},{"url":"https://www.netsarang.com/en/xshell-update-history/"},{"url":"https://www.paramiko.org/changelog.html"},{"url":"https://www.openssh.com/openbsd.html"},{"url":"https://github.com/openssh/openssh-portable/commits/master"},{"url":"https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ"},{"url":"https://www.bitvise.com/ssh-server-version-history"},{"url":"https://github.com/ronf/asyncssh/tags"},{"url":"https://gitlab.com/libssh/libssh-mirror/-/tags"},{"url":"https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/"},{"url":"https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42"},{"url":"https://www.openssh.com/txt/release-9.6"},{"url":"https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/"},{"url":"https://www.terrapin-attack.com"},{"url":"https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25"},{"url":"https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst"},{"url":"https://thorntech.com/cve-2023-48795-and-sftp-gateway/"},{"url":"https://github.com/warp-tech/russh/releases/tag/v0.40.2"},{"url":"https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0"},{"url":"https://www.openwall.com/lists/oss-security/2023/12/18/2"},{"url":"https://twitter.com/TrueSkrillor/status/1736774389725565005"},{"url":"https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d"},{"url":"https://github.com/paramiko/paramiko/issues/2337"},{"url":"https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg"},{"url":"https://news.ycombinator.com/item?id=38684904"},{"url":"https://news.ycombinator.com/item?id=38685286"},{"name":"[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2023/12/18/3"},{"url":"https://github.com/mwiede/jsch/issues/457"},{"url":"https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6"},{"url":"https://github.com/erlang/otp/releases/tag/OTP-26.2.1"},{"url":"https://github.com/advisories/GHSA-45x7-px36-x8w8"},{"url":"https://security-tracker.debian.org/tracker/source-package/libssh2"},{"url":"https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg"},{"url":"https://security-tracker.debian.org/tracker/CVE-2023-48795"},{"url":"https://bugzilla.suse.com/show_bug.cgi?id=1217950"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2254210"},{"url":"https://bugs.gentoo.org/920280"},{"url":"https://ubuntu.com/security/CVE-2023-48795"},{"url":"https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/"},{"url":"https://access.redhat.com/security/cve/cve-2023-48795"},{"url":"https://github.com/mwiede/jsch/pull/461"},{"url":"https://github.com/drakkan/sftpgo/releases/tag/v2.5.6"},{"url":"https://github.com/libssh2/libssh2/pull/1291"},{"url":"https://forum.netgate.com/topic/184941/terrapin-ssh-attack"},{"url":"https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5"},{"url":"https://github.com/rapier1/hpn-ssh/releases"},{"url":"https://github.com/proftpd/proftpd/issues/456"},{"url":"https://github.com/TeraTermProject/teraterm/releases/tag/v5.1"},{"url":"https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15"},{"url":"https://oryx-embedded.com/download/#changelog"},{"url":"https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update"},{"url":"https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22"},{"url":"https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab"},{"url":"https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3"},{"url":"https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC"},{"url":"https://crates.io/crates/thrussh/versions"},{"url":"https://github.com/NixOS/nixpkgs/pull/275249"},{"name":"[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2023/12/19/5"},{"url":"https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc"},{"url":"https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/"},{"name":"[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2023/12/20/3"},{"url":"http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html"},{"url":"https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES"},{"url":"https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES"},{"url":"https://github.com/apache/mina-sshd/issues/445"},{"url":"https://github.com/hierynomus/sshj/issues/916"},{"url":"https://github.com/janmojzis/tinyssh/issues/81"},{"url":"https://www.openwall.com/lists/oss-security/2023/12/20/3"},{"url":"https://security-tracker.debian.org/tracker/source-package/trilead-ssh2"},{"url":"https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16"},{"name":"FEDORA-2023-0733306be9","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"},{"name":"DSA-5586","tags":["vendor-advisory"],"url":"https://www.debian.org/security/2023/dsa-5586"},{"url":"https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508"},{"url":"https://www.theregister.com/2023/12/20/terrapin_attack_ssh"},{"url":"https://filezilla-project.org/versions.php"},{"url":"https://nova.app/releases/#v11.8"},{"url":"https://roumenpetrov.info/secsh/#news20231220"},{"url":"https://www.vandyke.com/products/securecrt/history.txt"},{"url":"https://help.panic.com/releasenotes/transmit5/"},{"url":"https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta"},{"url":"https://github.com/PowerShell/Win32-OpenSSH/issues/2189"},{"url":"https://winscp.net/eng/docs/history#6.2.2"},{"url":"https://www.bitvise.com/ssh-client-version-history#933"},{"url":"https://github.com/cyd01/KiTTY/issues/520"},{"name":"DSA-5588","tags":["vendor-advisory"],"url":"https://www.debian.org/security/2023/dsa-5588"},{"url":"https://github.com/ssh-mitm/ssh-mitm/issues/165"},{"url":"https://news.ycombinator.com/item?id=38732005"},{"name":"[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update","tags":["mailing-list"],"url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"},{"name":"GLSA-202312-16","tags":["vendor-advisory"],"url":"https://security.gentoo.org/glsa/202312-16"},{"name":"GLSA-202312-17","tags":["vendor-advisory"],"url":"https://security.gentoo.org/glsa/202312-17"},{"name":"FEDORA-2023-20feb865d8","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"},{"name":"FEDORA-2023-cb8c606fbb","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/"},{"name":"FEDORA-2023-e77300e4b5","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"},{"name":"FEDORA-2023-b87ec6cf47","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/"},{"name":"FEDORA-2023-153404713b","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/"},{"url":"https://security.netapp.com/advisory/ntap-20240105-0004/"},{"name":"FEDORA-2024-3bb23c77f3","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/"},{"name":"FEDORA-2023-55800423a8","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"},{"name":"FEDORA-2024-d946b9ad25","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"},{"name":"FEDORA-2024-71c2c6526c","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/"},{"name":"FEDORA-2024-39a8c72ea9","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"},{"url":"https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002"},{"name":"FEDORA-2024-ae653fb07b","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/"},{"name":"FEDORA-2024-2705241461","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"},{"name":"FEDORA-2024-fb32950d11","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/"},{"name":"FEDORA-2024-7b08207cdb","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"},{"name":"FEDORA-2024-06ebb70bdd","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"},{"name":"[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update","tags":["mailing-list"],"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html"},{"name":"[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update","tags":["mailing-list"],"url":"https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html"},{"name":"FEDORA-2024-a53b24023d","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"},{"name":"FEDORA-2024-3fd1bc9276","tags":["vendor-advisory"],"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"},{"url":"https://support.apple.com/kb/HT214084"},{"name":"20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4","tags":["mailing-list"],"url":"http://seclists.org/fulldisclosure/2024/Mar/21"},{"name":"[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update","tags":["mailing-list"],"url":"https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"},{"name":"[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2024/04/17/8"},{"name":"[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins","tags":["mailing-list"],"url":"http://www.openwall.com/lists/oss-security/2024/03/06/3"}]}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2023-48795","datePublished":"2023-12-18T00:00:00.000Z","dateReserved":"2023-11-20T00:00:00.000Z","dateUpdated":"2026-05-12T11:02:25.905Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2023-12-18 16:15:10","lastModifiedDate":"2026-05-12 11:16:15","problem_types":["CWE-354","n/a","CWE-354 CWE-354 Improper Validation of Integrity Check Value"],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":3.6}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*","versionEndExcluding":"9.6","matchCriteriaId":"5308FBBB-F738-41C5-97A4-E40118E957CD"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*","versionEndExcluding":"0.80","matchCriteriaId":"A9D807DB-9E20-4792-8A9F-4BFFC841BAB7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:filezilla-project:filezilla_client:*:*:*:*:*:*:*:*","versionEndExcluding":"3.66.4","matchCriteriaId":"42915485-A4DA-48DD-9C15-415D2D39DC52"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:panic:transmit_5:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.4","matchCriteriaId":"31FFE0AA-FC25-40DE-8EE9-7F4C80ABDE4F"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*","matchCriteriaId":"387021A0-AF36-463C-A605-32EA7DAC172E"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:panic:nova:*:*:*:*:*:*:*:*","versionEndExcluding":"11.8","matchCriteriaId":"F2FCF7EF-97D7-44CF-AC74-72D856901755"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:roumenpetrov:pkixssh:*:*:*:*:*:*:*:*","versionEndExcluding":"14.4","matchCriteriaId":"53CAD263-1C60-43BD-86A2-C8DB15FFB4C6"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*","versionEndExcluding":"6.2.2","matchCriteriaId":"8FA57F20-C9C1-40A7-B2CD-F3440CCF1D66"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bitvise:ssh_client:*:*:*:*:*:*:*:*","versionEndExcluding":"9.33","matchCriteriaId":"6209E375-10C7-4E65-A2E7-455A686717AC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:bitvise:ssh_server:*:*:*:*:*:*:*:*","versionEndExcluding":"9.32","matchCriteriaId":"1A05CC3C-19C5-4BAA-ABA2-EE1795E0BE81"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lcos:*:*:*:*:*:*:*:*","versionEndIncluding":"3.66.4","matchCriteriaId":"3A71B523-0778-46C6-A38B-64452E0BB6E7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lcos_fx:-:*:*:*:*:*:*:*","matchCriteriaId":"F1C91308-15E5-40AF-B4D5-3CAD7BC65DDF"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lcos_lx:-:*:*:*:*:*:*:*","matchCriteriaId":"418940E3-6DD1-4AA6-846A-03E059D0C681"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lcos_sx:4.20:*:*:*:*:*:*:*","matchCriteriaId":"411BA58A-33B6-44CA-B9D6-7F9042D46961"},{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lcos_sx:5.20:*:*:*:*:*:*:*","matchCriteriaId":"FA17A153-30E4-4731-8706-8F74FCA50993"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:lancom-systems:lanconfig:-:*:*:*:*:*:*:*","matchCriteriaId":"FB736F57-9BE3-4457-A10E-FA88D0932154"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:*","versionEndExcluding":"9.4.3","matchCriteriaId":"6EB8D02D-87F3-414D-A3EA-43F594DAAC1B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*","versionEndExcluding":"0.10.6","matchCriteriaId":"AAB481DA-FBFE-4CC2-9AE7-22025FA07494"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:net-ssh:net-ssh:7.2.0:*:*:*:*:ruby:*:*","matchCriteriaId":"3D6FD459-F8E8-4126-8097-D30B4639404A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ssh2_project:ssh2:*:*:*:*:*:node.js:*:*","versionEndIncluding":"1.11.0","matchCriteriaId":"69510F52-C699-4E7D-87EF-7000682888F0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*","versionEndIncluding":"1.3.8b","matchCriteriaId":"9461430B-3709-45B6-8858-2101F5AE4481"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*","versionEndIncluding":"12.4","matchCriteriaId":"B9A01DF3-E20E-4F29-B5CF-DDF717D01E74"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:crates:thrussh:*:*:*:*:*:*:*:*","versionEndExcluding":"0.35.1","matchCriteriaId":"D25EB73D-6145-4B7D-8F14-80FD0B458E99"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tera_term_project:tera_term:*:*:*:*:*:*:*:*","versionEndIncluding":"5.1","matchCriteriaId":"77594DEC-B5F7-4911-A13D-FFE91C74BAFA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oryx-embedded:cyclone_ssh:*:*:*:*:*:*:*:*","versionEndExcluding":"2.3.4","matchCriteriaId":"F8FF7E74-2351-4CD9-B717-FA28893293A1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*","versionEndIncluding":"10.6.0","matchCriteriaId":"82A93C12-FEB6-4E82-B283-0ED7820D807E"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netsarang:xshell_7:*:*:*:*:*:*:*:*","versionEndExcluding":"build__0144","matchCriteriaId":"B480AE79-2FA1-4281-9F0D-0DE812B9354D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*","versionEndExcluding":"3.4.0","matchCriteriaId":"826B6323-06F8-4B96-8771-3FA15A727B08"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*","matchCriteriaId":"932D137F-528B-4526-9A89-CD59FA1AB0FE"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*","matchCriteriaId":"DCC81071-B46D-4F5D-AC25-B4A4CCC20C73"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*","matchCriteriaId":"4B3000D2-35DF-4A93-9FC0-1AD3AB8349B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*","matchCriteriaId":"E315FC5C-FF19-43C9-A58A-CF2A5FF13824"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:ceph_storage:6.0:*:*:*:*:*:*:*","matchCriteriaId":"FA7EAD12-E398-44AF-9859-F3CA6C63BA6B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*","matchCriteriaId":"F4CFF558-3C47-480D-A2F0-BABF26042943"},{"vulnerable":true,"criteria":"cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*","matchCriteriaId":"7F6FB57C-2BC7-487C-96DD-132683AEB35D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*","matchCriteriaId":"77675CB7-67D7-44E9-B7FF-D224B3341AA5"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_gitops:-:*:*:*:*:*:*:*","matchCriteriaId":"C0AAA300-691A-4957-8B69-F6888CC971B1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_pipelines:-:*:*:*:*:*:*:*","matchCriteriaId":"45937289-2D64-47CB-A750-5B4F0D4664A0"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*","matchCriteriaId":"97321212-0E07-4CC2-A917-7B5F61AB9A5A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*","matchCriteriaId":"0E2C021C-A9F0-4EB4-ADED-81D8B57B4563"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:*","matchCriteriaId":"7BF8EFFB-5686-4F28-A68F-1A8854E098CE"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_virtualization:4:*:*:*:*:*:*:*","matchCriteriaId":"9C877879-B84B-471C-80CF-0656521CA8AB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*","matchCriteriaId":"379A5883-F6DF-41F5-9403-8D17F6605737"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*","matchCriteriaId":"B5B1D946-5978-4818-BF21-A43D9C1365E1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*","matchCriteriaId":"99B8A88B-0B31-4CFF-AFD7-C9D3DDD5790D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:cert-manager_operator_for_red_hat_openshift:-:*:*:*:*:*:*:*","matchCriteriaId":"6D5A7736-A403-4617-8790-18E46CB74DA6"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*","matchCriteriaId":"6E0DE4E1-5D8D-40F3-8AC8-C7F736966158"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*","matchCriteriaId":"88BF3B2C-B121-483A-AEF2-8082F6DA5310"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*","matchCriteriaId":"9EFEC7CA-8DDA-48A6-A7B6-1F1D14792890"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*","matchCriteriaId":"F0FD736A-8730-446A-BA3A-7B608DB62B0E"},{"vulnerable":true,"criteria":"cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:*:*:*","matchCriteriaId":"F4C504B6-3902-46E2-82B7-48AEC9CDD48D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:golang:crypto:*:*:*:*:*:*:*:*","versionEndExcluding":"0.17.0","matchCriteriaId":"F92E56DF-98DF-4328-B37E-4D5744E4103D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*","versionEndExcluding":"0.40.2","matchCriteriaId":"AC12508E-3C31-44EA-B4F3-29316BE9B189"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:*","versionEndExcluding":"2.5.6","matchCriteriaId":"1750028C-698D-4E84-B727-8A155A46ADEB"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","versionEndExcluding":"22.3.4.27","matchCriteriaId":"B38C0997-A8CC-473C-98CF-641FD21EB411"},{"vulnerable":true,"criteria":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","versionStartIncluding":"23.0","versionEndExcluding":"23.3.4.20","matchCriteriaId":"5887F3E2-9214-4FAE-8768-441D770E27C0"},{"vulnerable":true,"criteria":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","versionStartIncluding":"24.0","versionEndExcluding":"24.3.4.15","matchCriteriaId":"8D7CB988-94C4-45BE-AD9D-9C16899A71DF"},{"vulnerable":true,"criteria":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","versionStartIncluding":"25.0","versionEndExcluding":"25.3.2.8","matchCriteriaId":"EB749F4B-99FC-4AE8-BDB3-85B081B52F82"},{"vulnerable":true,"criteria":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","versionStartIncluding":"26.0","versionEndExcluding":"26.2.1","matchCriteriaId":"2380909A-BA9B-4A76-82F2-D2D0EF242E57"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:matez:jsch:*:*:*:*:*:*:*:*","versionEndExcluding":"0.2.15","matchCriteriaId":"61119DB3-4336-4D3B-863A-0CCF4146E5C1"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*","versionEndExcluding":"1.11.1","matchCriteriaId":"7BFDD272-3DF0-4E3F-B69A-E7ABF4B18B24"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:asyncssh_project:asyncssh:*:*:*:*:*:*:*:*","versionEndExcluding":"2.14.2","matchCriteriaId":"FAE46983-0ABC-49F7-AC18-A78FAC7E73AA"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*","versionEndExcluding":"2022.83","matchCriteriaId":"06BF3368-F232-4E6B-883E-A591EED5C827"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jadaptive:maverick_synergy_java_ssh_api:*:*:*:*:*:*:*:*","versionEndExcluding":"3.1.0-snapshot","matchCriteriaId":"36531FB6-5682-4BF1-9785-E9D6D1C4207B"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*","versionEndExcluding":"4.9.1.5","matchCriteriaId":"A86A51EA-B501-42F8-91E6-4EA97DED767C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*","versionStartIncluding":"4.10","versionEndExcluding":"4.11.1.7","matchCriteriaId":"70989970-E224-4D1C-941E-BBFB2AE7285C"},{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*","versionStartIncluding":"4.12","versionEndExcluding":"4.13.2.4","matchCriteriaId":"E7819CE3-2849-4D15-874B-F6A68EF6D65F"},{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*","versionStartIncluding":"4.14","versionEndExcluding":"4.15.3.1","matchCriteriaId":"F6A4DD8B-06AD-4F13-8F7E-1E2AAF81C119"},{"vulnerable":true,"criteria":"cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*","versionStartIncluding":"5.0","versionEndExcluding":"5.1.1","matchCriteriaId":"D91ED5E1-1D75-4B63-B0A2-B2EB6D4AC685"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:thorntech:sftp_gateway_firmware:*:*:*:*:*:*:*:*","versionEndExcluding":"3.4.6","matchCriteriaId":"83B1AF39-C0B9-4031-B19A-BDDD4F337273"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:*","versionEndIncluding":"23.09.1","matchCriteriaId":"2B71B0EF-888E-45E2-A055-F59CDCC1AFC7"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:netgate:pfsense_ce:*:*:*:*:*:*:*:*","versionEndIncluding":"2.7.2","matchCriteriaId":"8F23CDF7-2881-4B4E-B84F-4E04F4ED8CCF"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*","versionEndExcluding":"10.6.0","matchCriteriaId":"C1795F7A-203F-400E-B09C-0FAF16D01CFC"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:connectbot:sshlib:*:*:*:*:*:*:*:*","versionEndExcluding":"2.2.22","matchCriteriaId":"0D79DDDD-02F0-4C12-BE7F-1B9DF1722C7A"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*","versionEndIncluding":"2.11.0","matchCriteriaId":"E2D7B0CA-C01F-4296-9425-48299E3889C5"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:sshj:*:*:*:*:*:*:*:*","versionEndIncluding":"0.37.0","matchCriteriaId":"1C3EB0B8-9E76-4146-AB02-02E20B91D55C"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tinyssh:tinyssh:*:*:*:*:*:*:*:*","versionEndIncluding":"20230101","matchCriteriaId":"0582468A-149B-429F-978A-2AEDF4BE2606"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trilead:ssh2:6401:*:*:*:*:*:*:*","matchCriteriaId":"7E4BAF06-5A79-46D7-8C4F-E670BD6B7C2D"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:9bis:kitty:*:*:*:*:*:*:*:*","versionEndIncluding":"0.76.1.13","matchCriteriaId":"98321BF9-5E8F-4836-842C-47713B1C2775"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gentoo:security:-:*:*:*:*:*:*:*","matchCriteriaId":"76BDAFDE-4515-42E6-820F-38AF4A786CF2"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*","matchCriteriaId":"5920923E-0D52-44E5-801D-10B82846ED58"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*","matchCriteriaId":"CC559B26-5DFC-4B7A-A27C-B77DE755DFF9"},{"vulnerable":true,"criteria":"cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","matchCriteriaId":"B8EDB836-4E6A-4B71-B9B2-AA3E03E0F646"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","matchCriteriaId":"07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*","versionStartIncluding":"14.0","versionEndExcluding":"14.4","matchCriteriaId":"73160D1F-755B-46D2-969F-DF8E43BB1099"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2023","CveId":"48795","Ordinal":"1","Title":"CVE-2023-48795","CVE":"CVE-2023-48795","Year":"2023"},"notes":[{"CveYear":"2023","CveId":"48795","Ordinal":"1","NoteData":"The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.","Type":"Description","Title":"CVE-2023-48795"}]}}}