QID 38902

Date Published: 2023-07-19

QID 38902: OpenSSH Man-in-the-Middle (MITM) Attack Vulnerability

OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.

OpenSSH contains the following vulnerabilities:
CVE-2020-14145:The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.

Affected Versions:
OpenSSH 5.7-8.6

QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.

Successful exploitation allows man-in-the-middle attackers to target initial connection attempts

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to upgrade to OpenSSH 8.7 or later to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 38902

    Software Advisories
    Advisory ID Software Component Link
    CVE-2020-14145 URL Logo www.openssh.com/