New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security
ID: 33ddfc2a-26e7-514d-ad58-bd4c28a3e1b1
STIX ID: report--33ddfc2a-26e7-514d-ad58-bd4c28a3e1b1
Feed Name: The Hacker News
Threat Score
Security researchers disclosed CVE-2023-48795 (“Terrapin”), a prefix-truncation attack against SSH extension negotiation that allows an active MITM to truncate messages and downgrade connection security (potentially weakening client authentication and disabling countermeasures); multiple SSH implementations are affected, patches have been released, and Shadowserver estimates ~11 million internet-exposed SSH servers remain vulnerable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
