🔍 Search Results

Searching CVE for "openssh"

12 result(s)
CVE-2025-48416 HIGH 8.1

This CVE describes a vulnerability where an OpenSSH daemon has a hard-coded root password in /etc/shadow, but the default configuration disables root login via SSH. Attackers can bypass this restricti...

Published: May 21, 2025

CVE-2023-5616 MEDIUM 4.9

This vulnerability in Ubuntu's gnome-control-center fails to accurately display SSH remote login status when systemd socket activation is used for openssh-server. This could mislead users into believi...

Published: Apr 15, 2025

CVE-2025-32728 MEDIUM 4.3

OpenSSH versions before 10.0 have a bug where the DisableForwarding directive fails to properly disable X11 and agent forwarding as documented. This affects systems using OpenSSH with DisableForwardin...

Published: Apr 10, 2025

CVE-2025-30095 CRITICAL 9.0

This vulnerability allows attackers to conduct man-in-the-middle attacks against SSH connections using Dropbear, as affected systems share identical private host keys across installations. It impacts ...

Published: Mar 31, 2025

CVE-2025-26465 MEDIUM 6.8

This OpenSSH vulnerability allows machine-in-the-middle attacks when VerifyHostKeyDNS is enabled. Attackers can impersonate legitimate servers by exploiting error code mishandling during host key veri...

Published: Feb 18, 2025

CVE-2024-43615 HIGH 7.1

This vulnerability in Microsoft OpenSSH for Windows allows remote attackers to execute arbitrary code on affected systems. Attackers could exploit this to gain control of Windows servers running vulne...

Published: Oct 8, 2024

CVE-2024-38029 HIGH 7.5

This vulnerability in Microsoft's OpenSSH for Windows allows remote attackers to execute arbitrary code on affected systems. Attackers can exploit this to gain full control over vulnerable Windows ser...

Published: Oct 8, 2024

CVE-2024-7589 HIGH 8.1

CVE-2024-7589 is a race condition vulnerability in OpenSSH's sshd on FreeBSD systems that allows unauthenticated remote attackers to potentially execute arbitrary code with root privileges. The vulner...

Published: Aug 12, 2024

CVE-2024-6409 HIGH 7.0

A race condition vulnerability in OpenSSH's sshd server allows remote attackers to potentially execute code as an unprivileged user. The vulnerability occurs when SIGALRM signals are handled asynchron...

Published: Jul 8, 2024

CVE-2024-39894 HIGH 7.5

This vulnerability in OpenSSH allows attackers to perform timing attacks against password entry when echo is disabled (e.g., during su or sudo operations). The flaw in ObscureKeystrokeTiming logic cou...

Published: Jul 2, 2024

CVE-2023-51767 HIGH 7.0

This CVE describes a potential row hammer attack vulnerability in OpenSSH that could allow authentication bypass. An attacker with physical access to the same hardware could flip bits in memory to byp...

Published: Dec 24, 2023

CVE-2022-31124 HIGH 7.7

This vulnerability in openssh_key_parser allows attackers to expose sensitive key field values through error messages. Attackers can manipulate declared field lengths to trigger error messages contain...

Published: Jul 6, 2022