CVE-2023-48795
📛 CVE Title
CVE-2023-48795
Description
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- mitre
- CVSS severity
- MEDIUM
- CVSS score
- 5.9 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N- Effective score
- 5.9 / 10 MEDIUM source: CNA overview
- MSRC score
- 5.9 / 10 MEDIUM
- CWE(s)
-
CWE-354 - Reserved
- 2023-11-20
- Published
- 2023-12-18 01:00 UTC
- Last updated
- 2026-05-12 13:02 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2023/48xxx/CVE-2023-48795.json
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2023-12-18 16:15:10 UTC
- NVD last modified
- 2026-06-17 06:34:59 UTC
- NVD CVSS v3.1
- 5.9 / 10 MEDIUM source: nvd@nist.gov
- NVD CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N- Exploitability subscore
- 2.2 / 10
- Impact subscore
- 3.6 / 10
- EPSS score
- 0.9331 (probability of exploitation in next 30 days)
- EPSS percentile
- 99.83% vs all CVEs — higher = more likely to be exploited, as of 2026-07-27
NVD / KEV / EPSS data refreshed 2026-07-27 17:31 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2023-3093 - Assigner
- mitre
- Published
- Dec 18, 2023, 12:00:00 AM
- Updated
- May 12, 2026, 11:02:25 AM
- EUVD base score (CVSS 3.1)
-
5.9 / 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N - EUVD-reported EPSS
- 54.2100
- Vendors
- n/a
- Products
-
n/a (n/a)
- Aliases
-
GHSA-45x7-px36-x8w8
ENISA description: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
EUVD references (118)
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://matt.ucc.asn.au/dropbear/CHANGES
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://www.netsarang.com/en/xshell-update-history/
- https://www.paramiko.org/changelog.html
- https://www.openssh.com/openbsd.html
- https://github.com/openssh/openssh-portable/commits/master
- https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
- https://www.bitvise.com/ssh-server-version-history
- https://github.com/ronf/asyncssh/tags
- https://gitlab.com/libssh/libssh-mirror/-/tags
- https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
- https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
- https://www.openssh.com/txt/release-9.6
- https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
- https://www.terrapin-attack.com
- https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
- https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
- https://thorntech.com/cve-2023-48795-and-sftp-gateway/
- https://github.com/warp-tech/russh/releases/tag/v0.40.2
- https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
- https://www.openwall.com/lists/oss-security/2023/12/18/2
- https://twitter.com/TrueSkrillor/status/1736774389725565005
- https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
- https://github.com/paramiko/paramiko/issues/2337
- https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
- https://news.ycombinator.com/item?id=38684904
- https://news.ycombinator.com/item?id=38685286
- http://www.openwall.com/lists/oss-security/2023/12/18/3
- https://github.com/mwiede/jsch/issues/457
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
- https://github.com/erlang/otp/releases/tag/OTP-26.2.1
- https://github.com/advisories/GHSA-45x7-px36-x8w8
- https://security-tracker.debian.org/tracker/source-package/libssh2
- https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
- https://security-tracker.debian.org/tracker/CVE-2023-48795
- https://bugzilla.suse.com/show_bug.cgi?id=1217950
- https://bugzilla.redhat.com/show_bug.cgi?id=2254210
- https://bugs.gentoo.org/920280
- https://ubuntu.com/security/CVE-2023-48795
- https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
- https://access.redhat.com/security/cve/cve-2023-48795
- https://github.com/mwiede/jsch/pull/461
- https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
- https://github.com/libssh2/libssh2/pull/1291
- https://forum.netgate.com/topic/184941/terrapin-ssh-attack
- https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
- https://github.com/rapier1/hpn-ssh/releases
- https://github.com/proftpd/proftpd/issues/456
- https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
- https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
- https://oryx-embedded.com/download/#changelog
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
- https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
- https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
- https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
- https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
- https://crates.io/crates/thrussh/versions
- https://github.com/NixOS/nixpkgs/pull/275249
- http://www.openwall.com/lists/oss-security/2023/12/19/5
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
- https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
- http://www.openwall.com/lists/oss-security/2023/12/20/3
- http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
- https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
- https://github.com/apache/mina-sshd/issues/445
- https://github.com/hierynomus/sshj/issues/916
- https://github.com/janmojzis/tinyssh/issues/81
- https://www.openwall.com/lists/oss-security/2023/12/20/3
- https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
- https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/
- https://www.debian.org/security/2023/dsa-5586
- https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
- https://www.theregister.com/2023/12/20/terrapin_attack_ssh
- https://filezilla-project.org/versions.php
- https://nova.app/releases/#v11.8
- https://roumenpetrov.info/secsh/#news20231220
- https://www.vandyke.com/products/securecrt/history.txt
- https://help.panic.com/releasenotes/transmit5/
- https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
- https://github.com/PowerShell/Win32-OpenSSH/issues/2189
- https://winscp.net/eng/docs/history#6.2.2
- https://www.bitvise.com/ssh-client-version-history#933
- https://github.com/cyd01/KiTTY/issues/520
- https://www.debian.org/security/2023/dsa-5588
- https://github.com/ssh-mitm/ssh-mitm/issues/165
- https://news.ycombinator.com/item?id=38732005
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
- https://security.gentoo.org/glsa/202312-16
- https://security.gentoo.org/glsa/202312-17
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/
- https://security.netapp.com/advisory/ntap-20240105-0004/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/
- https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html
- https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/
- https://support.apple.com/kb/HT214084
- http://seclists.org/fulldisclosure/2024/Mar/21
- https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
- http://www.openwall.com/lists/oss-security/2024/04/17/8
- http://www.openwall.com/lists/oss-security/2024/03/06/3
Microsoft Security Response Center MSRC
Microsoft's vendor-authoritative record from the Security Update Guide — its own CVSS score, impact, severity rating, exploit assessment, and KB-article fixes. Refreshed 2026-08-12 01:06 UTC (source: CVRF).
- MS CVSS base score
- 5.9 / 10 (temporal 5.9)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N - Release
- 2024-Nov
Microsoft remediations / KB articles (7)
- cert-manager — Vendor Fix / CBL-Mariner (fixed build 1.11.2-7)
- https://nvd.nist.gov/vuln/detail/CVE-2023-48795 — None Available / cert-manager
- erlang — Vendor Fix / CBL-Mariner (fixed build 25.2-2)
- kubernetes — Vendor Fix / CBL-Mariner (fixed build 1.28.4-4)
- libssh — Vendor Fix / CBL-Mariner (fixed build 0.10.6-1)
- docker-buildx — Vendor Fix / CBL-Mariner (fixed build 0.14.0-1)
- kubevirt — Vendor Fix / CBL-Mariner (fixed build 1.2.0-9)
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| n/a | n/a |
n/a (affected)
|
— |
Affected products — CPE 2.3 (76) NVD
NVD's normalized CPE 2.3 matchers, used by vendor tools (vulnerability scanners, asset managers) for automated detection. Compare with the CNA's free-text "Affected products" section above.
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*cpe:2.3:a:filezilla-project:filezilla_client:*:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*cpe:2.3:a:panic:transmit_5:*:*:*:*:*:*:*:*cpe:2.3:a:panic:nova:*:*:*:*:*:*:*:*cpe:2.3:a:roumenpetrov:pkixssh:*:*:*:*:*:*:*:*cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*cpe:2.3:a:bitvise:ssh_client:*:*:*:*:*:*:*:*cpe:2.3:a:bitvise:ssh_server:*:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lcos:*:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lcos_fx:-:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lcos_lx:-:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lcos_sx:4.20:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lcos_sx:5.20:*:*:*:*:*:*:*cpe:2.3:o:lancom-systems:lanconfig:-:*:*:*:*:*:*:*cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:*cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*cpe:2.3:a:net-ssh:net-ssh:7.2.0:*:*:*:*:ruby:*:*cpe:2.3:a:ssh2_project:ssh2:*:*:*:*:*:node.js:*:*cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*cpe:2.3:a:crates:thrussh:*:*:*:*:*:*:*:*cpe:2.3:a:tera_term_project:tera_term:*:*:*:*:*:*:*:*cpe:2.3:a:oryx-embedded:cyclone_ssh:*:*:*:*:*:*:*:*cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*cpe:2.3:a:netsarang:xshell_7:*:*:*:*:*:*:*:*cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*cpe:2.3:a:redhat:ceph_storage:6.0:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_gitops:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_pipelines:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_virtualization:4:*:*:*:*:*:*:*cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:cert-manager_operator_for_red_hat_openshift:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:*:*:*cpe:2.3:a:golang:crypto:*:*:*:*:*:*:*:*cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:*cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*cpe:2.3:a:matez:jsch:*:*:*:*:*:*:*:*cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*cpe:2.3:a:asyncssh_project:asyncssh:*:*:*:*:*:*:*:*cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*cpe:2.3:a:jadaptive:maverick_synergy_java_ssh_api:*:*:*:*:*:*:*:*cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*cpe:2.3:o:thorntech:sftp_gateway_firmware:*:*:*:*:*:*:*:*cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:*cpe:2.3:a:netgate:pfsense_ce:*:*:*:*:*:*:*:*cpe:2.3:a:connectbot:sshlib:*:*:*:*:*:*:*:*cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*cpe:2.3:a:apache:sshj:*:*:*:*:*:*:*:*cpe:2.3:a:tinyssh:tinyssh:*:*:*:*:*:*:*:*cpe:2.3:a:trilead:ssh2:6401:*:*:*:*:*:*:*cpe:2.3:a:9bis:kitty:*:*:*:*:*:*:*:*cpe:2.3:a:gentoo:security:-:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
Vendor references (118)
References embedded in the original CVE record by the assigning CNA.
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://matt.ucc.asn.au/dropbear/CHANGES
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://www.netsarang.com/en/xshell-update-history/
- https://www.paramiko.org/changelog.html
- https://www.openssh.com/openbsd.html
- https://github.com/openssh/openssh-portable/commits/master
- https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
- https://www.bitvise.com/ssh-server-version-history
- https://github.com/ronf/asyncssh/tags
- https://gitlab.com/libssh/libssh-mirror/-/tags
- https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
- https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
- https://www.openssh.com/txt/release-9.6
- https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
- https://www.terrapin-attack.com
- https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
- https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
- https://thorntech.com/cve-2023-48795-and-sftp-gateway/
- https://github.com/warp-tech/russh/releases/tag/v0.40.2
- https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
- https://www.openwall.com/lists/oss-security/2023/12/18/2
- https://twitter.com/TrueSkrillor/status/1736774389725565005
- https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
- https://github.com/paramiko/paramiko/issues/2337
- https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
- https://news.ycombinator.com/item?id=38684904
- https://news.ycombinator.com/item?id=38685286
- [oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- https://github.com/mwiede/jsch/issues/457
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
- https://github.com/erlang/otp/releases/tag/OTP-26.2.1
- https://github.com/advisories/GHSA-45x7-px36-x8w8
- https://security-tracker.debian.org/tracker/source-package/libssh2
- https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
- https://security-tracker.debian.org/tracker/CVE-2023-48795
- https://bugzilla.suse.com/show_bug.cgi?id=1217950
- https://bugzilla.redhat.com/show_bug.cgi?id=2254210
- https://bugs.gentoo.org/920280
- https://ubuntu.com/security/CVE-2023-48795
- https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
- https://access.redhat.com/security/cve/cve-2023-48795
- https://github.com/mwiede/jsch/pull/461
- https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
- https://github.com/libssh2/libssh2/pull/1291
- https://forum.netgate.com/topic/184941/terrapin-ssh-attack
- https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
- https://github.com/rapier1/hpn-ssh/releases
- https://github.com/proftpd/proftpd/issues/456
- https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
- https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
- https://oryx-embedded.com/download/#changelog
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
- https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
- https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
- https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
- https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
- https://crates.io/crates/thrussh/versions
- https://github.com/NixOS/nixpkgs/pull/275249
- [oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
- https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
- [oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
- https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
- https://github.com/apache/mina-sshd/issues/445
- https://github.com/hierynomus/sshj/issues/916
- https://github.com/janmojzis/tinyssh/issues/81
- https://www.openwall.com/lists/oss-security/2023/12/20/3
- https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
- https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
- FEDORA-2023-0733306be9 vendor-advisory
- DSA-5586 vendor-advisory
- https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
- https://www.theregister.com/2023/12/20/terrapin_attack_ssh
- https://filezilla-project.org/versions.php
- https://nova.app/releases/#v11.8
- https://roumenpetrov.info/secsh/#news20231220
- https://www.vandyke.com/products/securecrt/history.txt
- https://help.panic.com/releasenotes/transmit5/
- https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
- https://github.com/PowerShell/Win32-OpenSSH/issues/2189
- https://winscp.net/eng/docs/history#6.2.2
- https://www.bitvise.com/ssh-client-version-history#933
- https://github.com/cyd01/KiTTY/issues/520
- DSA-5588 vendor-advisory
- https://github.com/ssh-mitm/ssh-mitm/issues/165
- https://news.ycombinator.com/item?id=38732005
- [debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update mailing-list
- GLSA-202312-16 vendor-advisory
- GLSA-202312-17 vendor-advisory
- FEDORA-2023-20feb865d8 vendor-advisory
- FEDORA-2023-cb8c606fbb vendor-advisory
- FEDORA-2023-e77300e4b5 vendor-advisory
- FEDORA-2023-b87ec6cf47 vendor-advisory
- FEDORA-2023-153404713b vendor-advisory
- https://security.netapp.com/advisory/ntap-20240105-0004/
- FEDORA-2024-3bb23c77f3 vendor-advisory
- FEDORA-2023-55800423a8 vendor-advisory
- FEDORA-2024-d946b9ad25 vendor-advisory
- FEDORA-2024-71c2c6526c vendor-advisory
- FEDORA-2024-39a8c72ea9 vendor-advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
- FEDORA-2024-ae653fb07b vendor-advisory
- FEDORA-2024-2705241461 vendor-advisory
- FEDORA-2024-fb32950d11 vendor-advisory
- FEDORA-2024-7b08207cdb vendor-advisory
- FEDORA-2024-06ebb70bdd vendor-advisory
- [debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update mailing-list
- [debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update mailing-list
- FEDORA-2024-a53b24023d vendor-advisory
- FEDORA-2024-3fd1bc9276 vendor-advisory
- https://support.apple.com/kb/HT214084
- 20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4 mailing-list
- [debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update mailing-list
- [oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client mailing-list
- [oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins mailing-list
MITRE references (117) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- GLSA-202312-16 vendor-advisory
- https://matt.ucc.asn.au/dropbear/CHANGES
- https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
- https://news.ycombinator.com/item?id=38684904
- https://news.ycombinator.com/item?id=38685286
- https://news.ycombinator.com/item?id=38732005
- https://nova.app/releases/#v11.8
- https://oryx-embedded.com/download/#changelog
- https://roumenpetrov.info/secsh/#news20231220
- https://security-tracker.debian.org/tracker/CVE-2023-48795
- https://security-tracker.debian.org/tracker/source-package/libssh2
- https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
- https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
- GLSA-202312-17 vendor-advisory
- https://security.netapp.com/advisory/ntap-20240105-0004/
- https://support.apple.com/kb/HT214084
- https://thorntech.com/cve-2023-48795-and-sftp-gateway/
- https://twitter.com/TrueSkrillor/status/1736774389725565005
- https://ubuntu.com/security/CVE-2023-48795
- https://winscp.net/eng/docs/history#6.2.2
- https://www.bitvise.com/ssh-client-version-history#933
- https://www.bitvise.com/ssh-server-version-history
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
- DSA-5586 vendor-advisory
- DSA-5588 vendor-advisory
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
- https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
- https://www.netsarang.com/en/xshell-update-history/
- https://www.openssh.com/openbsd.html
- https://www.openssh.com/txt/release-9.6
- https://www.openwall.com/lists/oss-security/2023/12/18/2
- https://www.openwall.com/lists/oss-security/2023/12/20/3
- https://www.paramiko.org/changelog.html
- https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
- https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
- https://www.terrapin-attack.com
- https://www.theregister.com/2023/12/20/terrapin_attack_ssh
- https://www.vandyke.com/products/securecrt/history.txt
- http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
- 20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4 mailing-list
- [oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- [oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- [oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack) mailing-list
- [oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins mailing-list
- [oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client mailing-list
- https://access.redhat.com/security/cve/cve-2023-48795
- https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
- https://bugs.gentoo.org/920280
- https://bugzilla.redhat.com/show_bug.cgi?id=2254210
- https://bugzilla.suse.com/show_bug.cgi?id=1217950
- https://crates.io/crates/thrussh/versions
- https://filezilla-project.org/versions.php
- https://forum.netgate.com/topic/184941/terrapin-ssh-attack
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
- https://github.com/NixOS/nixpkgs/pull/275249
- https://github.com/PowerShell/Win32-OpenSSH/issues/2189
- https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
- https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
- https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
- https://github.com/advisories/GHSA-45x7-px36-x8w8
- https://github.com/apache/mina-sshd/issues/445
- https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
- https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
- https://github.com/cyd01/KiTTY/issues/520
- https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
- https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
- https://github.com/erlang/otp/releases/tag/OTP-26.2.1
- https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
- https://github.com/hierynomus/sshj/issues/916
- https://github.com/janmojzis/tinyssh/issues/81
- https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
- https://github.com/libssh2/libssh2/pull/1291
- https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
- https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
- https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
- https://github.com/mwiede/jsch/issues/457
- https://github.com/mwiede/jsch/pull/461
- https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
- https://github.com/openssh/openssh-portable/commits/master
- https://github.com/paramiko/paramiko/issues/2337
- https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
- https://github.com/proftpd/proftpd/issues/456
- https://github.com/rapier1/hpn-ssh/releases
- https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
- https://github.com/ronf/asyncssh/tags
- https://github.com/ssh-mitm/ssh-mitm/issues/165
- https://github.com/warp-tech/russh/releases/tag/v0.40.2
- https://gitlab.com/libssh/libssh-mirror/-/tags
- https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
- https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
- https://help.panic.com/releasenotes/transmit5/
- https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
- [debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update mailing-list
- [debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update mailing-list
- [debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update mailing-list
- [debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update mailing-list
- FEDORA-2024-39a8c72ea9 vendor-advisory
- FEDORA-2024-3bb23c77f3 vendor-advisory
- FEDORA-2024-3fd1bc9276 vendor-advisory
- FEDORA-2023-20feb865d8 vendor-advisory
- FEDORA-2024-06ebb70bdd vendor-advisory
- FEDORA-2023-e77300e4b5 vendor-advisory
- FEDORA-2024-71c2c6526c vendor-advisory
- FEDORA-2024-d946b9ad25 vendor-advisory
- FEDORA-2024-ae653fb07b vendor-advisory
- FEDORA-2023-cb8c606fbb vendor-advisory
- FEDORA-2024-7b08207cdb vendor-advisory
- FEDORA-2024-2705241461 vendor-advisory
- FEDORA-2024-fb32950d11 vendor-advisory
- FEDORA-2023-153404713b vendor-advisory
- FEDORA-2024-a53b24023d vendor-advisory
- FEDORA-2023-55800423a8 vendor-advisory
- FEDORA-2023-0733306be9 vendor-advisory
- FEDORA-2023-b87ec6cf47 vendor-advisory
Web references (38)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- None Available msrc
- None Available msrc
- MSRC update guide: CVE-2023-48795 msrc
- https://errata.rockylinux.org/RLSA-2024:0628 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2024:2988 rapid7:errata.rockylinux.org
- https://errata.rockylinux.org/RLSA-2024:0606 rapid7:errata.rockylinux.org
- https://support.oracle.com/rs?type=doc&id=3000005.1 rapid7:support.oracle.com
- http://www.oracle.com/security-alerts/cpuapr2024.html rapid7:www.oracle.com
- https://jenkins.io/security/advisory/2024-04-17/ rapid7:jenkins.io
- https://aix.software.ibm.com/aix/efixes/security/openssh_advisory16.asc rapid7:aix.software.ibm.com
- https://support.apple.com/en-us/120895 rapid7:support.apple.com
- https://security.alpinelinux.org/vuln/CVE-2023-48795 rapid7:security.alpinelinux.org
- https://errata.almalinux.org/8/ALSA-2024-0628.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/9/ALSA-2024-1150.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/9/ALSA-2024-1130.html rapid7:errata.almalinux.org
- https://errata.almalinux.org/8/ALSA-2024-0606.html rapid7:errata.almalinux.org
- https://security.paloaltonetworks.com/CVE-2023-48795 rapid7:security.paloaltonetworks.com
- https://terrapin-attack.com rapid7:terrapin-attack.com
- https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_hpesbnw04673.json rapid7:csaf.arubanetworking.hpe.com
- https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_2024-005.json rapid7:csaf.arubanetworking.hpe.com
- https://csaf.arubanetworking.hpe.com/2024/hpe_aruba_networking_-_hpesbnw04678.json rapid7:csaf.arubanetworking.hpe.com
- https://alas.aws.amazon.com/AL2023/ALAS-2023-462.html rapid7:alas.aws.amazon.com
- https://alas.aws.amazon.com/AL2023/ALAS-2024-468.html rapid7:alas.aws.amazon.com
- https://advisory.splunk.com/advisories/SVD-2024-1012.html rapid7:advisory.splunk.com
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002 rapid7:psirt.global.sonicwall.com
- https://community.progress.com/s/article/ka7Pb0000016rc9IAA rapid7:community.progress.com
- https://www.dell.com/support/kbdoc/en-us/000284643/dsa-2025-086-dell-powerstore-t-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://www.dell.com/support/kbdoc/en-us/000242275/dsa-2024-432-dell-powerstore-x-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://www.dell.com/support/kbdoc/en-us/000228610/dsa-2024-398-dell-powerstore-family-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://www.dell.com/support/kbdoc/en-us/000225368/dsa-2024-225-dell-powerstore-family-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://www.dell.com/support/kbdoc/en-us/000221558/dsa-2024-021-idrac-8-and-idrac-9-security-update-for-cve-2023-48795 rapid7:www.dell.com
- https://www.dell.com/support/kbdoc/en-us/000229094/dsa-2024-408-dell-powerstore-family-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- http://cwe.mitre.org/data/definitions/354.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2023-48795 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3093 rapid7:euvd.enisa.europa.eu
- http://golang.org/x/crypto rapid7:golang.org
- https://www.dell.com/support/kbdoc/en-us/000223810/dsa-2024-158-dell-powerstore-x-security-update-for-multiple-vulnerabilities rapid7:www.dell.com
- https://www.cve.org/CVERecord?id=CVE-2023-48795 rapid7:www.cve.org
NVD-tagged references (257)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html cve@mitre.org Third Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html af854a3a-2127-422b-91ae-364da2661108 Third Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2024/Mar/21 cve@mitre.org Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2024/Mar/21 af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- http://www.openwall.com/lists/oss-security/2023/12/18/3 cve@mitre.org Mailing List
- http://www.openwall.com/lists/oss-security/2023/12/18/3 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- http://www.openwall.com/lists/oss-security/2023/12/19/5 cve@mitre.org Mailing List
- http://www.openwall.com/lists/oss-security/2023/12/19/5 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- http://www.openwall.com/lists/oss-security/2023/12/20/3 cve@mitre.org Mailing ListMitigation
- http://www.openwall.com/lists/oss-security/2023/12/20/3 af854a3a-2127-422b-91ae-364da2661108 Mailing ListMitigation
- http://www.openwall.com/lists/oss-security/2024/03/06/3 cve@mitre.org Mailing List
- http://www.openwall.com/lists/oss-security/2024/03/06/3 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/17/8 cve@mitre.org Mailing List
- http://www.openwall.com/lists/oss-security/2024/04/17/8 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://access.redhat.com/security/cve/cve-2023-48795 cve@mitre.org Third Party Advisory
- https://access.redhat.com/security/cve/cve-2023-48795 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/ cve@mitre.org Press/Media Coverage
- https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/ af854a3a-2127-422b-91ae-364da2661108 Press/Media Coverage
- https://bugs.gentoo.org/920280 cve@mitre.org Issue Tracking
- https://bugs.gentoo.org/920280 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2254210 cve@mitre.org Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2254210 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1217950 cve@mitre.org Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1217950 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://crates.io/crates/thrussh/versions cve@mitre.org Release Notes
- https://crates.io/crates/thrussh/versions af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://filezilla-project.org/versions.php cve@mitre.org Release Notes
- https://filezilla-project.org/versions.php af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://forum.netgate.com/topic/184941/terrapin-ssh-attack cve@mitre.org Issue Tracking
- https://forum.netgate.com/topic/184941/terrapin-ssh-attack af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6 cve@mitre.org Patch
- https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/NixOS/nixpkgs/pull/275249 cve@mitre.org Release Notes
- https://github.com/NixOS/nixpkgs/pull/275249 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/PowerShell/Win32-OpenSSH/issues/2189 cve@mitre.org Issue Tracking
- https://github.com/PowerShell/Win32-OpenSSH/issues/2189 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta cve@mitre.org Release Notes
- https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0 cve@mitre.org Patch
- https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/TeraTermProject/teraterm/releases/tag/v5.1 cve@mitre.org Release Notes
- https://github.com/TeraTermProject/teraterm/releases/tag/v5.1 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/advisories/GHSA-45x7-px36-x8w8 cve@mitre.org Third Party Advisory
- https://github.com/advisories/GHSA-45x7-px36-x8w8 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://github.com/apache/mina-sshd/issues/445 cve@mitre.org Issue Tracking
- https://github.com/apache/mina-sshd/issues/445 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab cve@mitre.org Patch
- https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22 cve@mitre.org Third Party Advisory
- https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://github.com/cyd01/KiTTY/issues/520 cve@mitre.org Issue Tracking
- https://github.com/cyd01/KiTTY/issues/520 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/drakkan/sftpgo/releases/tag/v2.5.6 cve@mitre.org Release Notes
- https://github.com/drakkan/sftpgo/releases/tag/v2.5.6 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42 cve@mitre.org Patch
- https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/erlang/otp/releases/tag/OTP-26.2.1 cve@mitre.org Release Notes
- https://github.com/erlang/otp/releases/tag/OTP-26.2.1 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d cve@mitre.org Patch
- https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/hierynomus/sshj/issues/916 cve@mitre.org Issue Tracking
- https://github.com/hierynomus/sshj/issues/916 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/janmojzis/tinyssh/issues/81 cve@mitre.org Issue Tracking
- https://github.com/janmojzis/tinyssh/issues/81 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5 cve@mitre.org Patch
- https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/libssh2/libssh2/pull/1291 cve@mitre.org Mitigation
- https://github.com/libssh2/libssh2/pull/1291 af854a3a-2127-422b-91ae-364da2661108 Mitigation
- https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25 cve@mitre.org Patch
- https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3 cve@mitre.org Patch
- https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15 cve@mitre.org Product
- https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15 af854a3a-2127-422b-91ae-364da2661108 Product
- https://github.com/mwiede/jsch/issues/457 cve@mitre.org Issue Tracking
- https://github.com/mwiede/jsch/issues/457 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/mwiede/jsch/pull/461 cve@mitre.org Release Notes
- https://github.com/mwiede/jsch/pull/461 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16 cve@mitre.org Patch
- https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16 af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/openssh/openssh-portable/commits/master cve@mitre.org Patch
- https://github.com/openssh/openssh-portable/commits/master af854a3a-2127-422b-91ae-364da2661108 Patch
- https://github.com/paramiko/paramiko/issues/2337 cve@mitre.org Issue Tracking
- https://github.com/paramiko/paramiko/issues/2337 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES cve@mitre.org Release Notes
- https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES cve@mitre.org Release Notes
- https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES cve@mitre.org Release Notes
- https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/proftpd/proftpd/issues/456 cve@mitre.org Issue Tracking
- https://github.com/proftpd/proftpd/issues/456 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/rapier1/hpn-ssh/releases cve@mitre.org Release Notes
- https://github.com/rapier1/hpn-ssh/releases af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst cve@mitre.org Release Notes
- https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/ronf/asyncssh/tags cve@mitre.org Release Notes
- https://github.com/ronf/asyncssh/tags af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://github.com/ssh-mitm/ssh-mitm/issues/165 cve@mitre.org Issue Tracking
- https://github.com/ssh-mitm/ssh-mitm/issues/165 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://github.com/warp-tech/russh/releases/tag/v0.40.2 cve@mitre.org Release Notes
- https://github.com/warp-tech/russh/releases/tag/v0.40.2 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://gitlab.com/libssh/libssh-mirror/-/tags cve@mitre.org Release Notes
- https://gitlab.com/libssh/libssh-mirror/-/tags af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ cve@mitre.org Mailing List
- https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg cve@mitre.org Mailing List
- https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://help.panic.com/releasenotes/transmit5/ cve@mitre.org Release Notes
- https://help.panic.com/releasenotes/transmit5/ af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/ cve@mitre.org Press/Media Coverage
- https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/ af854a3a-2127-422b-91ae-364da2661108 Press/Media Coverage
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html cve@mitre.org Mailing List
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html cve@mitre.org Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html cve@mitre.org Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html cve@mitre.org Mailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/ cve@mitre.org Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/ af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/ cve@mitre.org Mailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/ af854a3a-2127-422b-91ae-364da2661108 Mailing ListThird Party Advisory
- https://matt.ucc.asn.au/dropbear/CHANGES cve@mitre.org Release Notes
- https://matt.ucc.asn.au/dropbear/CHANGES af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC cve@mitre.org Patch
- https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC af854a3a-2127-422b-91ae-364da2661108 Patch
- https://news.ycombinator.com/item?id=38684904 cve@mitre.org Issue Tracking
- https://news.ycombinator.com/item?id=38684904 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://news.ycombinator.com/item?id=38685286 cve@mitre.org Issue Tracking
- https://news.ycombinator.com/item?id=38685286 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://news.ycombinator.com/item?id=38732005 cve@mitre.org Issue Tracking
- https://news.ycombinator.com/item?id=38732005 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://nova.app/releases/#v11.8 cve@mitre.org Release Notes
- https://nova.app/releases/#v11.8 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://oryx-embedded.com/download/#changelog cve@mitre.org Release Notes
- https://oryx-embedded.com/download/#changelog af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002 cve@mitre.org Third Party Advisory
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://roumenpetrov.info/secsh/#news20231220 cve@mitre.org Release Notes
- https://roumenpetrov.info/secsh/#news20231220 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://security-tracker.debian.org/tracker/CVE-2023-48795 cve@mitre.org Vendor Advisory
- https://security-tracker.debian.org/tracker/CVE-2023-48795 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/libssh2 cve@mitre.org Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/libssh2 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg cve@mitre.org Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://security-tracker.debian.org/tracker/source-package/trilead-ssh2 cve@mitre.org Issue Tracking
- https://security-tracker.debian.org/tracker/source-package/trilead-ssh2 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://security.gentoo.org/glsa/202312-16 cve@mitre.org Third Party Advisory
- https://security.gentoo.org/glsa/202312-16 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://security.gentoo.org/glsa/202312-17 cve@mitre.org Third Party Advisory
- https://security.gentoo.org/glsa/202312-17 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240105-0004/ cve@mitre.org Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240105-0004/ af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://support.apple.com/kb/HT214084 cve@mitre.org Third Party Advisory
- https://support.apple.com/kb/HT214084 af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://thorntech.com/cve-2023-48795-and-sftp-gateway/ cve@mitre.org Third Party Advisory
- https://thorntech.com/cve-2023-48795-and-sftp-gateway/ af854a3a-2127-422b-91ae-364da2661108 Third Party Advisory
- https://twitter.com/TrueSkrillor/status/1736774389725565005 cve@mitre.org Press/Media Coverage
- https://twitter.com/TrueSkrillor/status/1736774389725565005 af854a3a-2127-422b-91ae-364da2661108 Press/Media Coverage
- https://ubuntu.com/security/CVE-2023-48795 cve@mitre.org Vendor Advisory
- https://ubuntu.com/security/CVE-2023-48795 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://winscp.net/eng/docs/history#6.2.2 cve@mitre.org Release Notes
- https://winscp.net/eng/docs/history#6.2.2 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.bitvise.com/ssh-client-version-history#933 cve@mitre.org Release Notes
- https://www.bitvise.com/ssh-client-version-history#933 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.bitvise.com/ssh-server-version-history cve@mitre.org Release Notes
- https://www.bitvise.com/ssh-server-version-history af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html cve@mitre.org Release Notes
- https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update cve@mitre.org Release Notes
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.debian.org/security/2023/dsa-5586 cve@mitre.org Issue Tracking
- https://www.debian.org/security/2023/dsa-5586 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://www.debian.org/security/2023/dsa-5588 cve@mitre.org Issue Tracking
- https://www.debian.org/security/2023/dsa-5588 af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc cve@mitre.org Release Notes
- https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508 cve@mitre.org Vendor Advisory
- https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508 af854a3a-2127-422b-91ae-364da2661108 Vendor Advisory
- https://www.netsarang.com/en/xshell-update-history/ cve@mitre.org Release Notes
- https://www.netsarang.com/en/xshell-update-history/ af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.openssh.com/openbsd.html cve@mitre.org Release Notes
- https://www.openssh.com/openbsd.html af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.openssh.com/txt/release-9.6 cve@mitre.org Release Notes
- https://www.openssh.com/txt/release-9.6 af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.openwall.com/lists/oss-security/2023/12/18/2 cve@mitre.org Mailing List
- https://www.openwall.com/lists/oss-security/2023/12/18/2 af854a3a-2127-422b-91ae-364da2661108 Mailing List
- https://www.openwall.com/lists/oss-security/2023/12/20/3 cve@mitre.org Mailing ListMitigation
- https://www.openwall.com/lists/oss-security/2023/12/20/3 af854a3a-2127-422b-91ae-364da2661108 Mailing ListMitigation
- https://www.paramiko.org/changelog.html cve@mitre.org Release Notes
- https://www.paramiko.org/changelog.html af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/ cve@mitre.org Issue Tracking
- https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/ af854a3a-2127-422b-91ae-364da2661108 Issue Tracking
- https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/ cve@mitre.org Press/Media Coverage
- https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/ af854a3a-2127-422b-91ae-364da2661108 Press/Media Coverage
- https://www.terrapin-attack.com cve@mitre.org Exploit
- https://www.terrapin-attack.com af854a3a-2127-422b-91ae-364da2661108 Exploit
- https://www.theregister.com/2023/12/20/terrapin_attack_ssh cve@mitre.org Press/Media Coverage
- https://www.theregister.com/2023/12/20/terrapin_attack_ssh af854a3a-2127-422b-91ae-364da2661108 Press/Media Coverage
- https://www.vandyke.com/products/securecrt/history.txt cve@mitre.org Release Notes
- https://www.vandyke.com/products/securecrt/history.txt af854a3a-2127-422b-91ae-364da2661108 Release Notes
- https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party Advisory
- https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability af854a3a-2127-422b-91ae-364da2661108 ExploitThird Party Advisory
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-364175.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-769027.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-794697.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://cert-portal.siemens.com/productcert/html/ssa-915275.html 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
- https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html af854a3a-2127-422b-91ae-364da2661108
- https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html af854a3a-2127-422b-91ae-364da2661108
- https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/ af854a3a-2127-422b-91ae-364da2661108
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/ af854a3a-2127-422b-91ae-364da2661108
Remediations (10)
-
web:blog.qualys.com
Qualys helps identify and patch CVE-2023-48795 in SSH, reducing attack surface and enhancing security with CyberSecurity Asset Management (CSAM).
2026-05-23 02:07 UTC -
web:community.cisco.com
SSH Terrapin Prefix Truncation Weakness ( CVE-2023-48795 ) in cisco Catalyst 9300 We have run vulnerability cisco Catalyst 9300 and we find the above vulnerability. All software is up to date. #show ip ssh SSH Enabled - version 2.0 Authentication methods:publickey,keyboard-interactive,password Auth...
2026-05-23 02:07 UTC -
web:learn.microsoft.com
Currently, there is no patch available from Microsoft to address the Terrapin vulnerability so option 1 is not a solution. When certain customer services rely on the use of SSH Option 2 and 3 are both not an option or workable solution. Option 4 is not a solution Option 5 - while best practice is still not resolving the matter.
2026-05-23 02:07 UTC -
web:nvd.nist.gov
Information Technology Laboratory National Vulnerability Database Vulnerabilities
2026-05-23 02:07 UTC -
web:perifery.atlassian.net
This configuration change will help mitigate the Terrapin vulnerability by removing the affected ciphers while maintaining compatibility with supported systems. To verify the mitigation is applied download and run the following tool
2026-05-23 02:07 UTC -
web:security.paloaltonetworks.com
Palo Alto Networks Security Advisory: CVE-2023-48795 Impact of Terrapin SSH Attack The Terrapin attack allows an attacker with the ability to intercept SSH traffic on affected Palo Alto Networks products (through machine-in-the-middle or MitM attacks) to downgrade connection security and force the usage of less secure client authentication algorithms when an administrator or user connects to ...
2026-05-23 02:07 UTC -
web:support.huawei.com
In conclusion that the current storage version 6.1.5 is affected, and the solution is to upgrade to new patch version (6.1.8) that will resolve this vulnerability issue which The OpenSSH component version upgraded. For the mitigation operation on this CVE We suggest you to log in to each controller and execute the following command. By executing the command below, the SSH login algorithm will ...
2026-05-23 02:07 UTC -
web:www.darkreading.com
10 Steps to Detect, Prevent, and Remediate the Terrapin Vulnerability You don't have to stop using SSH keys to stay safe. This Tech Tip explains how to protect your system against CVE-2023-48795 .
2026-05-23 02:07 UTC -
web:www.huntress.com
The primary mitigation for CVE-2023-48795 is to patch your systems. Update all SSH clients and servers to the latest versions that include fixes for this vulnerability.
2026-05-23 02:07 UTC -
web:www.wiz.io
Understand the critical aspects of CVE-2023-48795 with a detailed vulnerability assessment, exploitation potential, affected technologies, and remediation guidance.
2026-05-23 02:07 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2023-48795.json.
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2025-11-04T22:05:21.417Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit"
},
{
"url": "https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://matt.ucc.asn.au/dropbear/CHANGES"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.netsarang.com/en/xshell-update-history/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.paramiko.org/changelog.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.openssh.com/openbsd.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/openssh/openssh-portable/commits/master"
},
{
"tags": [
"x_transferred"
],
"url": "https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.bitvise.com/ssh-server-version-history"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/ronf/asyncssh/tags"
},
{
"tags": [
"x_transferred"
],
"url": "https://gitlab.com/libssh/libssh-mirror/-/tags"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.openssh.com/txt/release-9.6"
},
{
"tags": [
"x_transferred"
],
"url": "https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.terrapin-attack.com"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst"
},
{
"tags": [
"x_transferred"
],
"url": "https://thorntech.com/cve-2023-48795-and-sftp-gateway/"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/warp-tech/russh/releases/tag/v0.40.2"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.openwall.com/lists/oss-security/2023/12/18/2"
},
{
"tags": [
"x_transferred"
],
"url": "https://twitter.com/TrueSkrillor/status/1736774389725565005"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/paramiko/paramiko/issues/2337"
},
{
"tags": [
"x_transferred"
],
"url": "https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=38684904"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=38685286"
},
{
"name": "[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/18/3"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/mwiede/jsch/issues/457"
},
{
"tags": [
"x_transferred"
],
"url": "https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/erlang/otp/releases/tag/OTP-26.2.1"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/advisories/GHSA-45x7-px36-x8w8"
},
{
"tags": [
"x_transferred"
],
"url": "https://security-tracker.debian.org/tracker/source-package/libssh2"
},
{
"tags": [
"x_transferred"
],
"url": "https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg"
},
{
"tags": [
"x_transferred"
],
"url": "https://security-tracker.debian.org/tracker/CVE-2023-48795"
},
{
"tags": [
"x_transferred"
],
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1217950"
},
{
"tags": [
"x_transferred"
],
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210"
},
{
"tags": [
"x_transferred"
],
"url": "https://bugs.gentoo.org/920280"
},
{
"tags": [
"x_transferred"
],
"url": "https://ubuntu.com/security/CVE-2023-48795"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/"
},
{
"tags": [
"x_transferred"
],
"url": "https://access.redhat.com/security/cve/cve-2023-48795"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/mwiede/jsch/pull/461"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/drakkan/sftpgo/releases/tag/v2.5.6"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/libssh2/libssh2/pull/1291"
},
{
"tags": [
"x_transferred"
],
"url": "https://forum.netgate.com/topic/184941/terrapin-ssh-attack"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/rapier1/hpn-ssh/releases"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/proftpd/proftpd/issues/456"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/TeraTermProject/teraterm/releases/tag/v5.1"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15"
},
{
"tags": [
"x_transferred"
],
"url": "https://oryx-embedded.com/download/#changelog"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3"
},
{
"tags": [
"x_transferred"
],
"url": "https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC"
},
{
"tags": [
"x_transferred"
],
"url": "https://crates.io/crates/thrussh/versions"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/NixOS/nixpkgs/pull/275249"
},
{
"name": "[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/19/5"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc"
},
{
"tags": [
"x_transferred"
],
"url": "https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/"
},
{
"name": "[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/20/3"
},
{
"tags": [
"x_transferred"
],
"url": "http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/apache/mina-sshd/issues/445"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/hierynomus/sshj/issues/916"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/janmojzis/tinyssh/issues/81"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.openwall.com/lists/oss-security/2023/12/20/3"
},
{
"tags": [
"x_transferred"
],
"url": "https://security-tracker.debian.org/tracker/source-package/trilead-ssh2"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16"
},
{
"name": "FEDORA-2023-0733306be9",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"
},
{
"name": "DSA-5586",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://www.debian.org/security/2023/dsa-5586"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.theregister.com/2023/12/20/terrapin_attack_ssh"
},
{
"tags": [
"x_transferred"
],
"url": "https://filezilla-project.org/versions.php"
},
{
"tags": [
"x_transferred"
],
"url": "https://nova.app/releases/#v11.8"
},
{
"tags": [
"x_transferred"
],
"url": "https://roumenpetrov.info/secsh/#news20231220"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.vandyke.com/products/securecrt/history.txt"
},
{
"tags": [
"x_transferred"
],
"url": "https://help.panic.com/releasenotes/transmit5/"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2189"
},
{
"tags": [
"x_transferred"
],
"url": "https://winscp.net/eng/docs/history#6.2.2"
},
{
"tags": [
"x_transferred"
],
"url": "https://www.bitvise.com/ssh-client-version-history#933"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/cyd01/KiTTY/issues/520"
},
{
"name": "DSA-5588",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://www.debian.org/security/2023/dsa-5588"
},
{
"tags": [
"x_transferred"
],
"url": "https://github.com/ssh-mitm/ssh-mitm/issues/165"
},
{
"tags": [
"x_transferred"
],
"url": "https://news.ycombinator.com/item?id=38732005"
},
{
"name": "[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"
},
{
"name": "GLSA-202312-16",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202312-16"
},
{
"name": "GLSA-202312-17",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://security.gentoo.org/glsa/202312-17"
},
{
"name": "FEDORA-2023-20feb865d8",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"
},
{
"name": "FEDORA-2023-cb8c606fbb",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/"
},
{
"name": "FEDORA-2023-e77300e4b5",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"
},
{
"name": "FEDORA-2023-b87ec6cf47",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/"
},
{
"name": "FEDORA-2023-153404713b",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/"
},
{
"tags": [
"x_transferred"
],
"url": "https://security.netapp.com/advisory/ntap-20240105-0004/"
},
{
"name": "FEDORA-2024-3bb23c77f3",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/"
},
{
"name": "FEDORA-2023-55800423a8",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"
},
{
"name": "FEDORA-2024-d946b9ad25",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"
},
{
"name": "FEDORA-2024-71c2c6526c",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/"
},
{
"name": "FEDORA-2024-39a8c72ea9",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"
},
{
"tags": [
"x_transferred"
],
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002"
},
{
"name": "FEDORA-2024-ae653fb07b",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/"
},
{
"name": "FEDORA-2024-2705241461",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"
},
{
"name": "FEDORA-2024-fb32950d11",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/"
},
{
"name": "FEDORA-2024-7b08207cdb",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"
},
{
"name": "FEDORA-2024-06ebb70bdd",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"
},
{
"name": "[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html"
},
{
"name": "[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html"
},
{
"name": "FEDORA-2024-a53b24023d",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"
},
{
"name": "FEDORA-2024-3fd1bc9276",
"tags": [
"vendor-advisory",
"x_transferred"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"
},
{
"tags": [
"x_transferred"
],
"url": "https://support.apple.com/kb/HT214084"
},
{
"name": "20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://seclists.org/fulldisclosure/2024/Mar/21"
},
{
"name": "[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"name": "[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2024/04/17/8"
},
{
"name": "[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins",
"tags": [
"mailing-list",
"x_transferred"
],
"url": "http://www.openwall.com/lists/oss-security/2024/03/06/3"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 5.9,
"baseSeverity": "MEDIUM",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2023-48795",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2023-12-22T05:01:05.519910Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-354",
"description": "CWE-354 Improper Validation of Integrity Check Value",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2025-08-27T20:45:57.733Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
},
{
"affected": [
{
"defaultStatus": "unknown",
"product": "RUGGEDCOM APE1808",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "SIPLUS S7-1500 CPU 1518-4 PN/DP MFP",
"vendor": "Siemens",
"versions": [
{
"lessThan": "*",
"status": "affected",
"version": "V3.1.5",
"versionType": "custom"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-05-12T11:02:25.905Z",
"orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
"shortName": "siemens-SADP"
},
"references": [
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-794697.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-364175.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-769027.html"
},
{
"url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
}
],
"x_adpType": "supplier"
}
],
"cna": {
"affected": [
{
"product": "n/a",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust."
}
],
"problemTypes": [
{
"descriptions": [
{
"description": "n/a",
"lang": "en",
"type": "text"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2024-05-01T18:06:23.972Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html"
},
{
"url": "https://matt.ucc.asn.au/dropbear/CHANGES"
},
{
"url": "https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES"
},
{
"url": "https://www.netsarang.com/en/xshell-update-history/"
},
{
"url": "https://www.paramiko.org/changelog.html"
},
{
"url": "https://www.openssh.com/openbsd.html"
},
{
"url": "https://github.com/openssh/openssh-portable/commits/master"
},
{
"url": "https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ"
},
{
"url": "https://www.bitvise.com/ssh-server-version-history"
},
{
"url": "https://github.com/ronf/asyncssh/tags"
},
{
"url": "https://gitlab.com/libssh/libssh-mirror/-/tags"
},
{
"url": "https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/"
},
{
"url": "https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42"
},
{
"url": "https://www.openssh.com/txt/release-9.6"
},
{
"url": "https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/"
},
{
"url": "https://www.terrapin-attack.com"
},
{
"url": "https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25"
},
{
"url": "https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst"
},
{
"url": "https://thorntech.com/cve-2023-48795-and-sftp-gateway/"
},
{
"url": "https://github.com/warp-tech/russh/releases/tag/v0.40.2"
},
{
"url": "https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0"
},
{
"url": "https://www.openwall.com/lists/oss-security/2023/12/18/2"
},
{
"url": "https://twitter.com/TrueSkrillor/status/1736774389725565005"
},
{
"url": "https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d"
},
{
"url": "https://github.com/paramiko/paramiko/issues/2337"
},
{
"url": "https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg"
},
{
"url": "https://news.ycombinator.com/item?id=38684904"
},
{
"url": "https://news.ycombinator.com/item?id=38685286"
},
{
"name": "[oss-security] 20231218 CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/18/3"
},
{
"url": "https://github.com/mwiede/jsch/issues/457"
},
{
"url": "https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6"
},
{
"url": "https://github.com/erlang/otp/releases/tag/OTP-26.2.1"
},
{
"url": "https://github.com/advisories/GHSA-45x7-px36-x8w8"
},
{
"url": "https://security-tracker.debian.org/tracker/source-package/libssh2"
},
{
"url": "https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg"
},
{
"url": "https://security-tracker.debian.org/tracker/CVE-2023-48795"
},
{
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1217950"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2254210"
},
{
"url": "https://bugs.gentoo.org/920280"
},
{
"url": "https://ubuntu.com/security/CVE-2023-48795"
},
{
"url": "https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/"
},
{
"url": "https://access.redhat.com/security/cve/cve-2023-48795"
},
{
"url": "https://github.com/mwiede/jsch/pull/461"
},
{
"url": "https://github.com/drakkan/sftpgo/releases/tag/v2.5.6"
},
{
"url": "https://github.com/libssh2/libssh2/pull/1291"
},
{
"url": "https://forum.netgate.com/topic/184941/terrapin-ssh-attack"
},
{
"url": "https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5"
},
{
"url": "https://github.com/rapier1/hpn-ssh/releases"
},
{
"url": "https://github.com/proftpd/proftpd/issues/456"
},
{
"url": "https://github.com/TeraTermProject/teraterm/releases/tag/v5.1"
},
{
"url": "https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15"
},
{
"url": "https://oryx-embedded.com/download/#changelog"
},
{
"url": "https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update"
},
{
"url": "https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22"
},
{
"url": "https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab"
},
{
"url": "https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3"
},
{
"url": "https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC"
},
{
"url": "https://crates.io/crates/thrussh/versions"
},
{
"url": "https://github.com/NixOS/nixpkgs/pull/275249"
},
{
"name": "[oss-security] 20231219 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/19/5"
},
{
"url": "https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc"
},
{
"url": "https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/"
},
{
"name": "[oss-security] 20231220 Re: CVE-2023-48795: Prefix Truncation Attacks in SSH Specification (Terrapin Attack)",
"tags": [
"mailing-list"
],
"url": "http://www.openwall.com/lists/oss-security/2023/12/20/3"
},
{
"url": "http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html"
},
{
"url": "https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES"
},
{
"url": "https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES"
},
{
"url": "https://github.com/apache/mina-sshd/issues/445"
},
{
"url": "https://github.com/hierynomus/sshj/issues/916"
},
{
"url": "https://github.com/janmojzis/tinyssh/issues/81"
},
{
"url": "https://www.openwall.com/lists/oss-security/2023/12/20/3"
},
{
"url": "https://security-tracker.debian.org/tracker/source-package/trilead-ssh2"
},
{
"url": "https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16"
},
{
"name": "FEDORA-2023-0733306be9",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/"
},
{
"name": "DSA-5586",
"tags": [
"vendor-advisory"
],
"url": "https://www.debian.org/security/2023/dsa-5586"
},
{
"url": "https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508"
},
{
"url": "https://www.theregister.com/2023/12/20/terrapin_attack_ssh"
},
{
"url": "https://filezilla-project.org/versions.php"
},
{
"url": "https://nova.app/releases/#v11.8"
},
{
"url": "https://roumenpetrov.info/secsh/#news20231220"
},
{
"url": "https://www.vandyke.com/products/securecrt/history.txt"
},
{
"url": "https://help.panic.com/releasenotes/transmit5/"
},
{
"url": "https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta"
},
{
"url": "https://github.com/PowerShell/Win32-OpenSSH/issues/2189"
},
{
"url": "https://winscp.net/eng/docs/history#6.2.2"
},
{
"url": "https://www.bitvise.com/ssh-client-version-history#933"
},
{
"url": "https://github.com/cyd01/KiTTY/issues/520"
},
{
"name": "DSA-5588",
"tags": [
"vendor-advisory"
],
"url": "https://www.debian.org/security/2023/dsa-5588"
},
{
"url": "https://github.com/ssh-mitm/ssh-mitm/issues/165"
},
{
"url": "https://news.ycombinator.com/item?id=38732005"
},
{
"name": "[debian-lts-announce] 20231226 [SECURITY] [DLA 3694-1] openssh security update",
"tags": [
"mailing-list"
],
"url": "https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html"
},
{
"name": "GLSA-202312-16",
"tags": [
"vendor-advisory"
],
"url": "https://security.gentoo.org/glsa/202312-16"
},
{
"name": "GLSA-202312-17",
"tags": [
"vendor-advisory"
],
"url": "https://security.gentoo.org/glsa/202312-17"
},
{
"name": "FEDORA-2023-20feb865d8",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/"
},
{
"name": "FEDORA-2023-cb8c606fbb",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/"
},
{
"name": "FEDORA-2023-e77300e4b5",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/"
},
{
"name": "FEDORA-2023-b87ec6cf47",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/"
},
{
"name": "FEDORA-2023-153404713b",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/"
},
{
"url": "https://security.netapp.com/advisory/ntap-20240105-0004/"
},
{
"name": "FEDORA-2024-3bb23c77f3",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/"
},
{
"name": "FEDORA-2023-55800423a8",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/"
},
{
"name": "FEDORA-2024-d946b9ad25",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/"
},
{
"name": "FEDORA-2024-71c2c6526c",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/"
},
{
"name": "FEDORA-2024-39a8c72ea9",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/"
},
{
"url": "https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002"
},
{
"name": "FEDORA-2024-ae653fb07b",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/"
},
{
"name": "FEDORA-2024-2705241461",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/"
},
{
"name": "FEDORA-2024-fb32950d11",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/"
},
{
"name": "FEDORA-2024-7b08207cdb",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/"
},
{
"name": "FEDORA-2024-06ebb70bdd",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/"
},
{
"name": "[debian-lts-announce] 20240125 [SECURITY] [DLA 3718-1] php-phpseclib security update",
"tags": [
"mailing-list"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html"
},
{
"name": "[debian-lts-announce] 20240125 [SECURITY] [DLA 3719-1] phpseclib security update",
"tags": [
"mailing-list"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html"
},
{
"name": "FEDORA-2024-a53b24023d",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/"
},
{
"name": "FEDORA-2024-3fd1bc9276",
"tags": [
"vendor-advisory"
],
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/"
},
{
"url": "https://support.apple.com/kb/HT214084"
},
{
"name": "20240313 APPLE-SA-03-07-2024-2 macOS Sonoma 14.4",
"tags": [
"mailing-list"
],
"url": "http://seclists.org/fulldisclosure/2024/Mar/21"
},
{
"name": "[debian-lts-announce] 20240425 [SECURITY] [DLA 3794-1] putty security update",
"tags": [
"mailing-list"
],
"url": "https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html"
},
{
"name": "[oss-security] 20240417 Terrapin vulnerability in Jenkins CLI client",
"tags": [
"mailing-list"
],
"url": "http://www.openwall.com/lists/oss-security/2024/04/17/8"
},
{
"name": "[oss-security] 20240306 Multiple vulnerabilities in Jenkins plugins",
"tags": [
"mailing-list"
],
"url": "http://www.openwall.com/lists/oss-security/2024/03/06/3"
}
]
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2023-48795",
"datePublished": "2023-12-18T00:00:00.000Z",
"dateReserved": "2023-11-20T00:00:00.000Z",
"dateUpdated": "2026-05-12T11:02:25.905Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}