logo

SSH Attack Surface (CVE-2023-48795): Find and Patch With CyberSecurity Asset Management Before the Grinch Arrives

ID: cae5b417-5e56-5998-8cd7-9fbebc3d210f

STIX ID: report--cae5b417-5e56-5998-8cd7-9fbebc3d210f

Feed Name: Qualys Blog

Threat Score
60/100

Date Published: 2023-12-22

Date Updated: 2026-04-28

Author: Siddharth Bhatia

...
...

This Qualys blog post describes CVE-2023-48795 (the “Terrapin Attack”), a vulnerability in OpenSSH (<9.6) and other SSH implementations that allows an active MITM to omit or delete SSH handshake messages, degrading security features and enabling interception or compromise; it outlines affected software, prevalence statistics across global assets, detection queries and QIDs for Qualys products, and recommended immediate and long-term remediation actions including patching, inventorying SSH instances, and improving key/access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.