logo

New Terrapin Flaw Could Let Attackers Downgrade SSH Protocol Security

ID: 33ddfc2a-26e7-514d-ad58-bd4c28a3e1b1

STIX ID: report--33ddfc2a-26e7-514d-ad58-bd4c28a3e1b1

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-01-01

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

Security researchers disclosed CVE-2023-48795 (“Terrapin”), a prefix-truncation attack against SSH extension negotiation that allows an active MITM to truncate messages and downgrade connection security (potentially weakening client authentication and disabling countermeasures); multiple SSH implementations are affected, patches have been released, and Shadowserver estimates ~11 million internet-exposed SSH servers remain vulnerable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.