Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-48795

5.9 · MEDIUM
Published Dec 18, 2023 openbsd CWE-354 EPSS 93.31% (100th pctl)

Overview

CVE-2023-48795 is a medium-severity vulnerability affecting openbsd openssh. It was published on December 18, 2023 and has a CVSS 3.1 base score of 5.9 (MEDIUM).

This vulnerability has a CVSS 3.1 base score of 5.9, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

Technical Description

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in [email protected] and (if CBC is used) the [email protected] MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.

Remediation

Check the references section for vendor advisories and patches from openbsd. Update openssh to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
openbsd openssh >= 0, < 9.6 Affected
putty putty >= 0, < 0.80 Affected
filezilla-project filezilla_client >= 0, < 3.66.4 Affected
panic transmit_5 >= 0, < 5.10.4 Affected
panic nova >= 0, < 11.8 Affected
roumenpetrov pkixssh >= 0, < 14.4 Affected
winscp winscp >= 0, < 6.2.2 Affected
bitvise ssh_client >= 0, < 9.33 Affected
bitvise ssh_server >= 0, < 9.32 Affected
lancom-systems lcos 0 Affected
vandyke securecrt >= 0, < 9.4.3 Affected
libssh libssh >= 0, < 0.10.6 Affected
ssh2_project ssh2 0 Affected
proftpd proftpd 0 Affected

Frequently Asked Questions

What is CVE-2023-48795?

CVE-2023-48795 is a medium-severity vulnerability affecting openbsd openssh. It was published on December 18, 2023 and has a CVSS 3.1 base score of 5.9 (MEDIUM).

How severe is CVE-2023-48795?

This vulnerability has a CVSS 3.1 base score of 5.9, rated MEDIUM. It can be exploited remotely over the network. No authentication or special privileges are required for exploitation.

How do I fix or remediate CVE-2023-48795?

Check the references section for vendor advisories and patches from openbsd. Update openssh to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-48795?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-48795 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.