QID 38902
Date Published: 2023-07-19
QID 38902: OpenSSH Man-in-the-Middle (MITM) Attack Vulnerability
OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.
OpenSSH contains the following vulnerabilities:
CVE-2020-14145:The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.
Affected Versions:
OpenSSH 5.7-8.6
QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.
Successful exploitation allows man-in-the-middle attackers to target initial connection attempts
- CVE-2020-14145 -
www.openssh.com/txt/release-8.7
CVEs related to QID 38902
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2020-14145 |
|