QID 379302
Date Published: 2024-02-12
QID 379302: Windows Secure Copy (WinSCP) Security Update
WinSCP is an SFTP, SCP, FTPS and FTP client for Windows
CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
Affected Software:
WinSCP versions prior to 6.2.2.
QID Detection Logic(Authenticated):
This QID checks for vulnerable versions of WinSCP by checking the WinSCP.exe file.
Successful exploitation allows remote attackers to bypass integrity checks.
Solution
For more information users are advised to visit the office site WinSCP site WinSCP Web site.
Vendor References
CVEs related to QID 379302
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 6.2.2 |
|