Vulnerability CVE-2023-48795: Information

Description

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

Severity: MEDIUM (5.9)
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Published: Dec. 18, 2023
Modified: Nov. 4, 2025
Error type identifier: CWE-354

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
cri-o1.27sisyphus1.27.6-alt11.27.8-alt2ALT-PU-2024-8173-6348675Fixed
cri-o1.27sisyphus_riscv641.27.6-alt11.27.8-alt2ALT-PU-2024-8511-1-Fixed
cri-o1.27sisyphus_loongarch641.27.6-alt11.27.8-alt2ALT-PU-2024-8530-1-Fixed
cri-o1.27p111.27.6-alt11.27.8-alt2ALT-PU-2024-8463-2349631Fixed
cri-o1.27p101.27.6-alt11.27.8-alt2ALT-PU-2024-8542-4349874Fixed
cri-o1.27c10f21.27.6-alt11.27.8-alt2ALT-PU-2024-8602-4350021Fixed
cri-o1.28sisyphus1.28.6-alt11.28.11-alt2ALT-PU-2024-8175-7348675Fixed
cri-o1.28sisyphus_riscv641.28.6-alt11.28.11-alt2ALT-PU-2024-8513-1-Fixed
cri-o1.28sisyphus_loongarch641.28.6-alt11.28.11-alt2ALT-PU-2024-8532-1-Fixed
cri-o1.28p111.28.6-alt11.28.11-alt2ALT-PU-2024-8461-2349631Fixed
cri-o1.28p101.28.6-alt11.28.11-alt2ALT-PU-2024-8544-4349874Fixed
cri-o1.28c10f21.28.6-alt11.28.11-alt2ALT-PU-2024-8605-4350021Fixed
dropbearsisyphus2022.83-alt12025.89-alt1ALT-PU-2023-8858-1331906Fixed
dropbearsisyphus_e2k2022.83-alt22024.86-alt1ALT-PU-2024-4421-1-Fixed
dropbearsisyphus_loongarch642022.83-alt22025.89-alt1ALT-PU-2024-2144-1-Fixed
dropbearp112022.83-alt12024.86-alt1ALT-PU-2023-8858-1331906Fixed
dropbearp102022.83-alt22022.83-alt2ALT-PU-2024-4252-2343137Fixed
dropbearp10_e2k2022.83-alt22022.83-alt2ALT-PU-2024-4514-1-Fixed
dropbearc10f22024.85-alt12024.85-alt1ALT-PU-2024-7175-3345878Fixed
erlangsisyphus26.2.5.3-alt126.2.5.11-alt3ALT-PU-2024-12987-4357883Fixed
erlangsisyphus_loongarch6426.2.5.3-alt126.2.5.11-alt3ALT-PU-2024-13247-1-Fixed
erlangp1126.2.5.3-alt126.2.5.11-alt1ALT-PU-2024-13209-3358194Fixed
erlangp1026.2.5.3-alt126.2.5.11-alt1ALT-PU-2024-15421-3362342Fixed
erlangc10f226.2.5.3-alt126.2.5.11-alt1ALT-PU-2024-13219-2358196Fixed
filezillasisyphus3.66.4-alt13.69.6-alt1ALT-PU-2023-8681-1337126Fixed
filezillap113.66.4-alt13.69.6-alt1ALT-PU-2023-8681-1337126Fixed
flannelp100.27.3-alt10.27.3-alt1ALT-PU-2025-13603-4398481Fixed
flannelc10f20.25.1-alt20.28.2-alt1ALT-PU-2024-8180-5348644Fixed
libsshsisyphus0.10.6-alt10.11.4-alt1ALT-PU-2024-1249-2338050Fixed
libsshsisyphus_e2k0.10.6-alt10.11.4-alt1ALT-PU-2024-1279-1-Fixed
libsshsisyphus_riscv640.10.6-alt10.11.4-alt1ALT-PU-2024-2714-1-Fixed
libsshsisyphus_loongarch640.10.6-alt10.11.4-alt1ALT-PU-2024-1440-1-Fixed
libsshp110.10.6-alt10.11.4-alt1ALT-PU-2024-1249-2338050Fixed
libsshp100.10.6-alt10.10.6-alt1ALT-PU-2024-1251-3338051Fixed
libsshp10_e2k0.10.6-alt10.10.6-alt1ALT-PU-2024-1381-1-Fixed
libsshc10f20.10.6-alt10.11.4-alt1ALT-PU-2024-1250-2338361Fixed
libsshc9f20.10.6-alt10.10.6-alt1ALT-PU-2024-1622-5339475Fixed
libssh2sisyphus1.11.0-alt21.11.1-alt1ALT-PU-2024-1561-2339356Fixed
libssh2sisyphus_e2k1.11.0-alt21.11.0-alt2ALT-PU-2024-1699-1-Fixed
libssh2sisyphus_riscv641.11.0-alt21.11.1-alt1ALT-PU-2024-3231-1-Fixed
libssh2sisyphus_loongarch641.11.0-alt21.11.1-alt1ALT-PU-2024-1601-1-Fixed
libssh2p111.11.0-alt21.11.0-alt2ALT-PU-2024-1561-2339356Fixed
libssh2p101.11.0-alt21.11.0-alt2ALT-PU-2024-1563-2339351Fixed
libssh2p10_e2k1.11.0-alt21.11.0-alt2ALT-PU-2024-1964-1-Fixed
libssh2c10f21.11.0-alt21.11.0-alt2ALT-PU-2024-1562-2339357Fixed
libssh2c9f21.11.0-alt21.11.0-alt2ALT-PU-2024-4039-4342773Fixed
openquantumsafe-opensshc10f28.9p1.202310-alt38.9p1.202310-alt3ALT-PU-2024-17393-3365537Fixed
opensshsisyphus9.5p1-alt29.6p1-alt6ALT-PU-2024-1247-3338314Fixed
opensshsisyphus_e2k9.5p1-alt29.6p1-alt5ALT-PU-2024-8876-1-Fixed
opensshsisyphus_riscv649.5p1-alt29.6p1-alt6ALT-PU-2024-2876-1-Fixed
opensshsisyphus_loongarch649.5p1-alt29.6p1-alt6ALT-PU-2024-1471-1-Fixed
opensshp119.5p1-alt29.6p1-alt5ALT-PU-2024-1247-3338314Fixed
opensshp107.9p1-alt4.p10.47.9p1-alt4.p10.8ALT-PU-2024-1190-4338315Fixed
opensshp10_e2k7.9p1-alt4.p10.47.9p1-alt4.p10.8ALT-PU-2024-1468-1-Fixed
opensshp97.9p1-alt4.p10.67.9p1-alt4.p10.7ALT-PU-2024-12012-4356748Fixed
opensshc10f27.9p1-alt4.p10.47.9p1-alt4.p10.8ALT-PU-2024-1333-3338780Fixed
opensshc9f27.9p1-alt4.p10.47.9p1-alt4.p10.8ALT-PU-2024-1569-4339369Fixed
openssh-gostcryptosisyphus9.6p1-alt1.gost9.6p1-alt6.gostALT-PU-2024-7269-3344956Fixed
openssh-gostcryptop119.6p1-alt2.gost9.6p1-alt3.gostALT-PU-2024-9513-3351933Fixed
openssh-gostcryptop107.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.5ALT-PU-2024-3921-4342647Fixed
openssh-gostcryptop97.9p1-alt4.gost.p10.37.9p1-alt4.gost.p10.4ALT-PU-2024-12010-4356748Fixed
openssh-gostcryptoc10f27.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.5ALT-PU-2024-4182-3343010Fixed
openssh-gostcryptoc9f27.9p1-alt4.gost.p10.17.9p1-alt4.gost.p10.5ALT-PU-2024-4077-3342832Fixed
podmansisyphus4.8.3-alt15.7.1-alt1ALT-PU-2024-1096-2337978Fixed
podmansisyphus_riscv644.8.3-alt15.7.1-alt1ALT-PU-2024-1101-1-Fixed
podmansisyphus_loongarch644.8.3-alt15.7.1-alt1ALT-PU-2024-1104-1-Fixed
podmanp114.8.3-alt15.7.0-alt1ALT-PU-2024-1096-2337978Fixed
proftpdsisyphus1.3.9-alt0.1.rc21.3.9-alt1ALT-PU-2024-11072-3330474Fixed
proftpdsisyphus_riscv641.3.9-alt0.1.rc21.3.9-alt1ALT-PU-2024-11097-1-Fixed
proftpdsisyphus_loongarch641.3.9-alt0.1.rc21.3.9-alt1ALT-PU-2024-11104-1-Fixed
puttysisyphus0.81-alt10.83-alt1ALT-PU-2024-6830-2345428Fixed
puttysisyphus_e2k0.81-alt10.81-alt2ALT-PU-2024-6884-1-Fixed
puttysisyphus_loongarch640.81-alt10.83-alt1ALT-PU-2024-6895-1-Fixed
puttyp110.81-alt10.81-alt2ALT-PU-2024-6830-2345428Fixed
puttyp100.81-alt20.81-alt2ALT-PU-2024-9848-2351368Fixed
puttyp10_e2k0.81-alt20.81-alt2ALT-PU-2024-9995-1-Fixed
puttyc10f20.81-alt20.81-alt2ALT-PU-2024-9398-2351553Fixed
puttyc9f20.81-alt20.81-alt2ALT-PU-2024-9396-3351555Fixed
python3-module-asyncsshsisyphus2.14.2-alt12.22.0-alt1ALT-PU-2024-8723-2350401Fixed
python3-module-asyncsshsisyphus_e2k2.19.0-alt12.19.0-alt1ALT-PU-2025-4257-1-Fixed
python3-module-asyncsshsisyphus_riscv642.14.2-alt12.22.0-alt1ALT-PU-2024-8745-1-Fixed
python3-module-asyncsshsisyphus_loongarch642.14.2-alt12.22.0-alt1ALT-PU-2024-8754-1-Fixed
python3-module-asyncsshp112.19.0-alt12.19.0-alt1ALT-PU-2025-2804-5370642Fixed
python3-module-paramikosisyphus3.4.0-alt14.0.0-alt1.1ALT-PU-2024-1940-3339791Fixed
python3-module-paramikosisyphus_e2k3.4.0-alt13.5.1-alt1ALT-PU-2024-2375-1-Fixed
python3-module-paramikosisyphus_riscv643.4.0-alt14.0.0-alt1.1ALT-PU-2024-3369-1-Fixed
python3-module-paramikosisyphus_loongarch643.4.0-alt14.0.0-alt1.1ALT-PU-2024-2089-1-Fixed
python3-module-paramikop113.4.0-alt13.5.1-alt1ALT-PU-2024-1940-3339791Fixed
resticprofilesisyphus0.25.0-alt10.32.0-alt1ALT-PU-2024-2064-3340331Fixed
resticprofilesisyphus_loongarch640.25.0-alt10.32.0-alt1ALT-PU-2024-2140-1-Fixed
resticprofilep110.25.0-alt10.26.0-alt1.1ALT-PU-2024-2064-3340331Fixed
resticprofilec10f20.25.0-alt10.26.0-alt1.1ALT-PU-2024-2064-3340331Fixed
tinysshsisyphus20240101-alt120260401-alt1ALT-PU-2024-1001-3337569Fixed
tinysshsisyphus_e2k20240101-alt120240101-alt1ALT-PU-2024-1054-1-Fixed
tinysshsisyphus_loongarch6420240101-alt120260301-alt1ALT-PU-2024-1023-1-Fixed
tinysshp1120240101-alt120240101-alt1ALT-PU-2024-1001-3337569Fixed
vaultsisyphus1.13.12-alt31.13.12-alt8ALT-PU-2024-9089-4350936Fixed
vaultsisyphus_riscv641.13.12-alt41.13.12-alt8ALT-PU-2024-9105-1-Fixed
vaultsisyphus_loongarch641.13.12-alt41.13.12-alt8ALT-PU-2024-9117-1-Fixed
vaultp111.13.12-alt41.13.12-alt8ALT-PU-2024-9408-3351672Fixed
vaultp101.13.12-alt41.13.12-alt6ALT-PU-2024-9897-4351699Fixed
vaultc10f21.13.12-alt41.13.12-alt8ALT-PU-2024-9901-4352701Fixed
vaultc9f21.13.12-alt51.13.12-alt8ALT-PU-2024-12410-3356974Fixed

References to Advisories, Solutions, and Tools

Hyperlink
Resource
http://packetstormsecurity.com/files/176280/Terrapin-SSH-Connection-Weakening.html
  • Third Party Advisory
  • VDB Entry
http://seclists.org/fulldisclosure/2024/Mar/21
  • Mailing List
  • Third Party Advisory
http://www.openwall.com/lists/oss-security/2023/12/18/3
  • Mailing List
http://www.openwall.com/lists/oss-security/2023/12/19/5
  • Mailing List
http://www.openwall.com/lists/oss-security/2023/12/20/3
  • Mailing List
  • Mitigation
http://www.openwall.com/lists/oss-security/2024/03/06/3
  • Mailing List
http://www.openwall.com/lists/oss-security/2024/04/17/8
  • Mailing List
https://access.redhat.com/security/cve/cve-2023-48795
  • Third Party Advisory
https://arstechnica.com/security/2023/12/hackers-can-break-ssh-channel-integrity-using-novel-data-corruption-attack/
  • Press/Media Coverage
https://bugs.gentoo.org/920280
  • Issue Tracking
https://bugzilla.redhat.com/show_bug.cgi?id=2254210
  • Issue Tracking
https://bugzilla.suse.com/show_bug.cgi?id=1217950
  • Issue Tracking
https://crates.io/crates/thrussh/versions
  • Release Notes
https://filezilla-project.org/versions.php
  • Release Notes
https://forum.netgate.com/topic/184941/terrapin-ssh-attack
  • Issue Tracking
https://git.libssh.org/projects/libssh.git/commit/?h=stable-0.10&id=10e09e273f69e149389b3e0e5d44b8c221c2e7f6
  • Patch
https://github.com/NixOS/nixpkgs/pull/275249
  • Release Notes
https://github.com/PowerShell/Win32-OpenSSH/issues/2189
  • Issue Tracking
https://github.com/PowerShell/Win32-OpenSSH/releases/tag/v9.5.0.0p1-Beta
  • Release Notes
https://github.com/TeraTermProject/teraterm/commit/7279fbd6ef4d0c8bdd6a90af4ada2899d786eec0
  • Patch
https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
  • Release Notes
https://github.com/advisories/GHSA-45x7-px36-x8w8
  • Third Party Advisory
https://github.com/apache/mina-sshd/issues/445
  • Issue Tracking
https://github.com/connectbot/sshlib/commit/5c8b534f6e97db7ac0e0e579331213aa25c173ab
  • Patch
https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
  • Third Party Advisory
https://github.com/cyd01/KiTTY/issues/520
  • Issue Tracking
https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
  • Release Notes
https://github.com/erlang/otp/blob/d1b43dc0f1361d2ad67601169e90a7fc50bb0369/lib/ssh/doc/src/notes.xml#L39-L42
  • Patch
https://github.com/erlang/otp/releases/tag/OTP-26.2.1
  • Release Notes
https://github.com/golang/crypto/commit/9d2ee975ef9fe627bf0a6f01c1f69e8ef1d4f05d
  • Patch
https://github.com/hierynomus/sshj/issues/916
  • Issue Tracking
https://github.com/janmojzis/tinyssh/issues/81
  • Issue Tracking
https://github.com/jtesta/ssh-audit/commit/8e972c5e94b460379fe0c7d20209c16df81538a5
  • Patch
https://github.com/libssh2/libssh2/pull/1291
  • Mitigation
https://github.com/mkj/dropbear/blob/17657c36cce6df7716d5ff151ec09a665382d5dd/CHANGES#L25
  • Patch
https://github.com/mscdex/ssh2/commit/97b223f8891b96d6fc054df5ab1d5a1a545da2a3
  • Patch
https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
  • Product
https://github.com/mwiede/jsch/issues/457
  • Issue Tracking
https://github.com/mwiede/jsch/pull/461
  • Release Notes
https://github.com/net-ssh/net-ssh/blob/2e65064a52d73396bfc3806c9196fc8108f33cd8/CHANGES.txt#L14-L16
  • Patch
https://github.com/openssh/openssh-portable/commits/master
  • Patch
https://github.com/paramiko/paramiko/issues/2337
  • Issue Tracking
https://github.com/proftpd/proftpd/blob/0a7ea9b0ba9fcdf368374a226370d08f10397d99/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/d21e7a2e47e9b38f709bec58e3fa711f759ad0e1/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
  • Release Notes
https://github.com/proftpd/proftpd/issues/456
  • Issue Tracking
https://github.com/rapier1/hpn-ssh/releases
  • Release Notes
https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
  • Release Notes
https://github.com/ronf/asyncssh/tags
  • Release Notes
https://github.com/ssh-mitm/ssh-mitm/issues/165
  • Issue Tracking
https://github.com/warp-tech/russh/releases/tag/v0.40.2
  • Release Notes
https://gitlab.com/libssh/libssh-mirror/-/tags
  • Release Notes
https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
  • Mailing List
https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
  • Mailing List
https://help.panic.com/releasenotes/transmit5/
  • Release Notes
https://jadaptive.com/important-java-ssh-security-update-new-ssh-vulnerability-discovered-cve-2023-48795/
  • Press/Media Coverage
https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
  • Mailing List
https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html
  • Mailing List
  • Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html
  • Mailing List
  • Third Party Advisory
https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3CAYYW35MUTNO65RVAELICTNZZFMT2XS/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BL5KTLOSLH2KHRN4HCXJPK3JUVLDGEL6/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CHHITS4PUOZAKFIUBQAQZC7JWXMOYE4B/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F7EYCFQCTSGJXWO3ZZ44MGKFC5HA7G3Y/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KEOTKBUPZXHE3F352JBYNTSNRXYLWD6P/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KMZCVGUGJZZVDPCVDA7TEB22VUCNEXDD/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/
  • Mailing List
  • Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/
  • Vendor Advisory
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QI3EHAHABFQK7OABNCSF5GMYP6TONTI7/
  • Mailing List
  • Third Party Advisory
https://matt.ucc.asn.au/dropbear/CHANGES
  • Release Notes
https://nest.pijul.com/pijul/thrussh/changes/D6H7OWTTMHHX6BTB3B6MNBOBX2L66CBL4LGSEUSAI2MCRCJDQFRQC
  • Patch
https://news.ycombinator.com/item?id=38684904
  • Issue Tracking
https://news.ycombinator.com/item?id=38685286
  • Issue Tracking
https://news.ycombinator.com/item?id=38732005
  • Issue Tracking
https://nova.app/releases/#v11.8
  • Release Notes
https://oryx-embedded.com/download/#changelog
  • Release Notes
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
  • Third Party Advisory
https://roumenpetrov.info/secsh/#news20231220
  • Release Notes
https://security-tracker.debian.org/tracker/CVE-2023-48795
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/libssh2
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/proftpd-dfsg
  • Vendor Advisory
https://security-tracker.debian.org/tracker/source-package/trilead-ssh2
  • Issue Tracking
https://security.gentoo.org/glsa/202312-16
  • Third Party Advisory
https://security.gentoo.org/glsa/202312-17
  • Third Party Advisory
https://security.netapp.com/advisory/ntap-20240105-0004/
  • Third Party Advisory
https://support.apple.com/kb/HT214084
  • Third Party Advisory
https://thorntech.com/cve-2023-48795-and-sftp-gateway/
  • Third Party Advisory
https://twitter.com/TrueSkrillor/status/1736774389725565005
  • Press/Media Coverage
https://ubuntu.com/security/CVE-2023-48795
  • Vendor Advisory
https://winscp.net/eng/docs/history#6.2.2
  • Release Notes
https://www.bitvise.com/ssh-client-version-history#933
  • Release Notes
https://www.bitvise.com/ssh-server-version-history
  • Release Notes
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
  • Release Notes
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
  • Release Notes
https://www.debian.org/security/2023/dsa-5586
  • Issue Tracking
https://www.debian.org/security/2023/dsa-5588
  • Issue Tracking
https://www.freebsd.org/security/advisories/FreeBSD-SA-23:19.openssh.asc
  • Release Notes
https://www.lancom-systems.de/service-support/allgemeine-sicherheitshinweise#c243508
  • Vendor Advisory
https://www.netsarang.com/en/xshell-update-history/
  • Release Notes
https://www.openssh.com/openbsd.html
  • Release Notes
https://www.openssh.com/txt/release-9.6
  • Release Notes
https://www.openwall.com/lists/oss-security/2023/12/18/2
  • Mailing List
https://www.openwall.com/lists/oss-security/2023/12/20/3
  • Mailing List
  • Mitigation
https://www.paramiko.org/changelog.html
  • Release Notes
https://www.reddit.com/r/sysadmin/comments/18idv52/cve202348795_why_is_this_cve_still_undisclosed/
  • Issue Tracking
https://www.suse.com/c/suse-addresses-the-ssh-v2-protocol-terrapin-attack-aka-cve-2023-48795/
  • Press/Media Coverage
https://www.terrapin-attack.com
  • Exploit
https://www.theregister.com/2023/12/20/terrapin_attack_ssh
  • Press/Media Coverage
https://www.vandyke.com/products/securecrt/history.txt
  • Release Notes
https://lists.debian.org/debian-lts-announce/2024/09/msg00042.html
    https://lists.debian.org/debian-lts-announce/2024/11/msg00032.html
      https://lists.debian.org/debian-lts-announce/2025/04/msg00028.html
        https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/33XHJUB6ROFUOH2OQNENFROTVH6MHSHA/
          https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3JIMLVBDWOP4FUPXPTB4PGHHIOMGFLQE/
            https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3YQLUQWLIHDB5QCXQEX7HXHAWMOKPP5O/
              https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6Y74KVCPEPT4MVU3LHDWCNNOXOE5ZLUR/
                https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/APYIXIQOVDCRWLHTGB4VYMAUIAQLKYJ3/
                  https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/C3AFMZ6MH2UHHOPIWT5YLSFV3D2VB3AC/
                    https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HYEDEXIKFKTUJIN43RG4B7T5ZS6MHUSP/
                      https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/I724O3LSRCPO4WNVIXTZCT4VVRMXMMSG/
                        https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/L5Y6MNNVAPIJSXJERQ6PKZVCIUXSNJK7/
                          https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LZQVUHWVWRH73YBXUQJOD6CKHDQBU3DM/
                            https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MKQRBF3DWMWPH36LBCOBUTSIZRTPEZXB/
                              https://www.vicarius.io/vsociety/posts/cve-2023-48795-detect-openssh-vulnerabilit
                              • Exploit
                              • Third Party Advisory
                              https://www.vicarius.io/vsociety/posts/cve-2023-48795-mitigate-openssh-vulnerability
                              • Exploit
                              • Third Party Advisory
                              BDU:2023-08853
                                GHSA-45x7-px36-x8w8
                                    1. cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      9.6

                                      cpe:2.3:a:putty:putty:*:*:*:*:*:*:*:*
                                      End excluding
                                      0.80

                                      cpe:2.3:a:filezilla-project:filezilla_client:*:*:*:*:*:*:*:*
                                      End excluding
                                      3.66.4

                                      cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:panic:transmit_5:*:*:*:*:*:*:*:*
                                      End excluding
                                      5.10.4

                                      cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:panic:nova:*:*:*:*:*:*:*:*
                                      End excluding
                                      11.8

                                      cpe:2.3:a:roumenpetrov:pkixssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      14.4

                                      cpe:2.3:a:winscp:winscp:*:*:*:*:*:*:*:*
                                      End excluding
                                      6.2.2

                                      cpe:2.3:a:bitvise:ssh_client:*:*:*:*:*:*:*:*
                                      End excluding
                                      9.33

                                      cpe:2.3:a:bitvise:ssh_server:*:*:*:*:*:*:*:*
                                      End excluding
                                      9.32

                                      cpe:2.3:o:lancom-systems:lcos:*:*:*:*:*:*:*:*
                                      End including
                                      3.66.4

                                      cpe:2.3:o:lancom-systems:lcos_fx:-:*:*:*:*:*:*:*

                                      cpe:2.3:o:lancom-systems:lcos_lx:-:*:*:*:*:*:*:*

                                      cpe:2.3:o:lancom-systems:lcos_sx:4.20:*:*:*:*:*:*:*

                                      cpe:2.3:o:lancom-systems:lcos_sx:5.20:*:*:*:*:*:*:*

                                      cpe:2.3:o:lancom-systems:lanconfig:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:vandyke:securecrt:*:*:*:*:*:*:*:*
                                      End excluding
                                      9.4.3

                                      cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      0.10.6

                                      cpe:2.3:a:net-ssh:net-ssh:7.2.0:*:*:*:*:ruby:*:*

                                      cpe:2.3:a:ssh2_project:ssh2:*:*:*:*:*:node.js:*:*
                                      End including
                                      1.11.0

                                      cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*
                                      End including
                                      1.3.8b

                                      cpe:2.3:o:freebsd:freebsd:*:*:*:*:*:*:*:*
                                      End including
                                      12.4

                                      cpe:2.3:a:crates:thrussh:*:*:*:*:*:*:*:*
                                      End excluding
                                      0.35.1

                                      cpe:2.3:a:tera_term_project:tera_term:*:*:*:*:*:*:*:*
                                      End including
                                      5.1

                                      cpe:2.3:a:oryx-embedded:cyclone_ssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      2.3.4

                                      cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
                                      End including
                                      10.6.0

                                      cpe:2.3:a:netsarang:xshell_7:*:*:*:*:*:*:*:*
                                      End excluding
                                      build__0144

                                      cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
                                      End excluding
                                      3.4.0

                                      cpe:2.3:a:redhat:openshift_container_platform:4.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openstack_platform:16.1:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openstack_platform:16.2:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openstack_platform:17.1:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:ceph_storage:6.0:*:*:*:*:*:*:*

                                      cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*

                                      cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_serverless:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_gitops:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_pipelines:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_developer_tools_and_services:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_api_for_data_protection:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_virtualization:4:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:storage:3.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:discovery:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:openshift_dev_spaces:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:cert-manager_operator_for_red_hat_openshift:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:advanced_cluster_security:3.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:redhat:advanced_cluster_security:4.0:*:*:*:*:*:*:*

                                      cpe:2.3:a:golang:crypto:*:*:*:*:*:*:*:*
                                      End excluding
                                      0.17.0

                                      cpe:2.3:a:russh_project:russh:*:*:*:*:*:rust:*:*
                                      End excluding
                                      0.40.2

                                      cpe:2.3:a:sftpgo_project:sftpgo:*:*:*:*:*:*:*:*
                                      End excluding
                                      2.5.6

                                      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
                                      End excluding
                                      22.3.4.27

                                      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
                                      Start including
                                      23.0
                                      End excluding
                                      23.3.4.20

                                      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
                                      Start including
                                      24.0
                                      End excluding
                                      24.3.4.15

                                      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
                                      Start including
                                      25.0
                                      End excluding
                                      25.3.2.8

                                      cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
                                      Start including
                                      26.0
                                      End excluding
                                      26.2.1

                                      cpe:2.3:a:matez:jsch:*:*:*:*:*:*:*:*
                                      End excluding
                                      0.2.15

                                      cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:*
                                      End excluding
                                      1.11.1

                                      cpe:2.3:a:asyncssh_project:asyncssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      2.14.2

                                      cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      2022.83

                                      cpe:2.3:a:jadaptive:maverick_synergy_java_ssh_api:*:*:*:*:*:*:*:*
                                      End excluding
                                      3.1.0-snapshot

                                      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
                                      End excluding
                                      4.9.1.5

                                      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
                                      Start including
                                      4.10
                                      End excluding
                                      4.11.1.7

                                      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
                                      Start including
                                      4.12
                                      End excluding
                                      4.13.2.4

                                      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
                                      Start including
                                      4.14
                                      End excluding
                                      4.15.3.1

                                      cpe:2.3:a:ssh:ssh:*:*:*:*:*:*:*:*
                                      Start including
                                      5.0
                                      End excluding
                                      5.1.1

                                      cpe:2.3:o:thorntech:sftp_gateway_firmware:*:*:*:*:*:*:*:*
                                      End excluding
                                      3.4.6

                                      cpe:2.3:a:netgate:pfsense_plus:*:*:*:*:*:*:*:*
                                      End including
                                      23.09.1

                                      cpe:2.3:a:netgate:pfsense_ce:*:*:*:*:*:*:*:*
                                      End including
                                      2.7.2

                                      cpe:2.3:a:crushftp:crushftp:*:*:*:*:*:*:*:*
                                      End excluding
                                      10.6.0

                                      cpe:2.3:a:connectbot:sshlib:*:*:*:*:*:*:*:*
                                      End excluding
                                      2.2.22

                                      cpe:2.3:a:apache:sshd:*:*:*:*:*:*:*:*
                                      End including
                                      2.11.0

                                      cpe:2.3:a:apache:sshj:*:*:*:*:*:*:*:*
                                      End including
                                      0.37.0

                                      cpe:2.3:a:tinyssh:tinyssh:*:*:*:*:*:*:*:*
                                      End including
                                      20230101

                                      cpe:2.3:a:trilead:ssh2:6401:*:*:*:*:*:*:*

                                      cpe:2.3:a:9bis:kitty:*:*:*:*:*:*:*:*
                                      End including
                                      0.76.1.13

                                      cpe:2.3:a:gentoo:security:-:*:*:*:*:*:*:*

                                      cpe:2.3:o:debian:debian_linux:-:*:*:*:*:*:*:*

                                      cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

                                      cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*

                                      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

                                      cpe:2.3:o:apple:macos:*:*:*:*:*:*:*:*
                                      Start including
                                      14.0
                                      End excluding
                                      14.4