USN-7292-1

    Dashboard / Vulnerabilities / USN-7292-1

    USN-7292-1

    Published: 25 Feb 2025Last Modified: 27 Apr 2026

    Summary: Several security issues were fixed in Dropbear

    Details: Manfred Kaiser discovered that Dropbear through 2020.81 does not properly check the available authentication methods in the client-side SSH code. An attacker could use this vulnerability to gain unauthorized access to remote systems. (CVE-2021-36369) Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that the SSH transport protocol implementation in Dropbear had weak integrity checks. An attacker could use this vulnerability to bypass security features like encryption and integrity checks. (CVE-2023-48795)

    Affected packages

    Package

    Name: dropbear

    Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/bionic

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2017.75-3ubuntu0.1~esm1

    Affected versions

    2017.75-2

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-7292-1 | CVE-DB