NA

CVE-2023-46445

Published: 14/11/2023 Updated: 22/12/2023
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 0

Vulnerability Summary

An issue in AsyncSSH prior to 2.14.1 allows malicious users to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

asyncssh project asyncssh

Vendor Advisories

Debian Bug report logs - #1056000 python-asyncssh: CVE-2023-46445 Package: src:python-asyncssh; Maintainer for src:python-asyncssh is Debian Python Team <team+python@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 15 Nov 2023 20:57:02 UTC Severity: important Tags: security, upstr ...

Github Repositories

This repository contains the artifacts for the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation".

Artifacts for Terrapin This repository contains artifacts for the paper "Terrapin Attack: Breaking SSH Channel Integrity By Sequence Number Manipulation", accepted at 33rd USENIX Security Symposium The code in this repository contains, among other artifacts, proof-of-concept attack proxies for the following CVEs: CVE-2023-48795 (general protocol flaw) CVE-2023-46445

Recent Articles

SSH shaken, not stirred by Terrapin vulnerability
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources No need to panic, but grab those updates or mitigations anyway just to be safe

A vulnerability in the SSH protocol can be exploited by a well-placed adversary to weaken the security of people's connections, if conditions are right. In a successful man-in-the-middle attack, the adversary may be able to force SSH clients to use weaker authentication methods and disable some defense mechanisms. It is hard right now to pin down the true realistic impact of the flaw because it all depends on individual client-server configurations, implementations of the protocol, and other var...