CVE Feed

    Dashboard / CVE / CVE-2023-48795

    CVE-2023-48795

    The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in [email protected] and (if CBC is used) the [email protected] MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

    Published:Dec 18, 2023
    Last Modified:May 12, 2026
    EPS:Dec 18, 2023
    EPSS Score:0.53559
    CVSS Score:5.9

    Affected Products

    Vendor
    9bis
    Product
    Kitty
    Vendor
    Apache
    Product
    Sshd
    Vendor
    Apache
    Product
    Sshj
    Vendor
    Apple
    Product
    Macos
    Vendor
    Asyncssh Project
    Product
    Asyncssh
    Vendor
    Bitvise
    Product
    Ssh Client
    Vendor
    Bitvise
    Product
    Ssh Server
    Vendor
    Connectbot
    Product
    Sshlib
    Vendor
    Crates
    Product
    Thrussh
    Vendor
    Crushftp
    Product
    Crushftp
    Vendor
    Debian
    Product
    Debian Linux
    Vendor
    Dropbear Ssh Project
    Product
    Dropbear Ssh
    Vendor
    Erlang
    Product
    Erlang\/otp
    Vendor
    Fedoraproject
    Product
    Fedora
    Vendor
    Filezilla-project
    Product
    Filezilla Client
    Vendor
    Freebsd
    Product
    Freebsd
    Vendor
    Gentoo
    Product
    Security
    Vendor
    Golang
    Product
    Crypto
    Vendor
    Jadaptive
    Product
    Maverick Synergy Java Ssh Api
    Vendor
    Lancom-systems
    Product
    Lanconfig
    Vendor
    Lancom-systems
    Product
    Lcos
    Vendor
    Lancom-systems
    Product
    Lcos Fx
    Vendor
    Lancom-systems
    Product
    Lcos Lx
    Vendor
    Lancom-systems
    Product
    Lcos Sx
    Vendor
    Libssh
    Product
    Libssh
    Vendor
    Libssh2
    Product
    Libssh2
    Vendor
    Matez
    Product
    Jsch
    Vendor
    Net-ssh
    Product
    Net-ssh
    Vendor
    Netgate
    Product
    Pfsense Ce
    Vendor
    Netgate
    Product
    Pfsense Plus
    Vendor
    Netsarang
    Product
    Xshell 7
    Vendor
    Openbsd
    Product
    Openssh
    Vendor
    Oryx-embedded
    Product
    Cyclone Ssh
    Vendor
    Panic
    Product
    Nova
    Vendor
    Panic
    Product
    Transmit 5
    Vendor
    Paramiko
    Product
    Paramiko
    Vendor
    Proftpd
    Product
    Proftpd
    Vendor
    Putty
    Product
    Putty
    Vendor
    Redhat
    Product
    Advanced Cluster Security
    Vendor
    Redhat
    Product
    Camel Quarkus
    Vendor
    Redhat
    Product
    Ceph Storage
    Vendor
    Redhat
    Product
    Cert-manager Operator For Red Hat Openshift
    Vendor
    Redhat
    Product
    Container Native Virtualization
    Vendor
    Redhat
    Product
    Discovery
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Jboss Enterprise Application Platform
    Vendor
    Redhat
    Product
    Keycloak
    Vendor
    Redhat
    Product
    Ocp Tools
    Vendor
    Redhat
    Product
    Openshift
    Vendor
    Redhat
    Product
    Openshift Api Data Protection
    Vendor
    Redhat
    Product
    Openshift Api For Data Protection
    Vendor
    Redhat
    Product
    Openshift Builds
    Vendor
    Redhat
    Product
    Openshift Container Platform
    Vendor
    Redhat
    Product
    Openshift Data Foundation
    Vendor
    Redhat
    Product
    Openshift Dev Spaces
    Vendor
    Redhat
    Product
    Openshift Developer Tools And Services
    Vendor
    Redhat
    Product
    Openshift Gitops
    Vendor
    Redhat
    Product
    Openshift Pipelines
    Vendor
    Redhat
    Product
    Openshift Serverless
    Vendor
    Redhat
    Product
    Openshift Virtualization
    Vendor
    Redhat
    Product
    Openstack
    Vendor
    Redhat
    Product
    Openstack Platform
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Redhat
    Product
    Serverless
    Vendor
    Redhat
    Product
    Single Sign-on
    Vendor
    Redhat
    Product
    Storage
    Vendor
    Roumenpetrov
    Product
    Pkixssh
    Vendor
    Russh Project
    Product
    Russh
    Vendor
    Sftpgo Project
    Product
    Sftpgo
    Vendor
    Ssh
    Product
    Ssh
    Vendor
    Ssh2 Project
    Product
    Ssh2
    Vendor
    Tera Term Project
    Product
    Tera Term
    Vendor
    Thorntech
    Product
    Sftp Gateway Firmware
    Vendor
    Tinyssh
    Product
    Tinyssh
    Vendor
    Trilead
    Product
    Ssh2
    Vendor
    Vandyke
    Product
    Securecrt
    Vendor
    Winscp
    Product
    Winscp

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High