SSH shaken, not stirred by Terrapin vulnerability
ID: f6ee1ebc-e384-5970-a6d9-9d0a78856388
STIX ID: report--f6ee1ebc-e384-5970-a6d9-9d0a78856388
Feed Name: The Register (Security)
The report describes the Terrapin Attack, a prefix-truncation man-in-the-middle vulnerability in the SSH protocol (CVE-2023-48795) and related AsyncSSH implementation flaws (CVE-2023-46445, CVE-2023-46446). Researchers published technical details and PoC artifacts showing how injected plaintext 'ignore' messages during the SSH handshake can allow an attacker to block later extension messages and thereby downgrade authentication, disable countermeasures, and in specific configurations even leak partial secrets; the write-up notes that many servers support exploitable algorithms, patches and updates from OpenSSH, PuTTY, libssh and AsyncSSH are available, and mitigations include upgrading and disabling vulnerable cipher modes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
