Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.
CVSS Details
- CVSS 3.1 Base Score: 3.7
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Apply OS X security update 2009-006 | Dec 16, 2011 | Nov 19, 2008 |
| Centos_linux | — | Upgrade opensshUpgrade openssh-serverUpgrade openssh-clientsUpgrade openssh-askpass | Dec 1, 2016 | Nov 19, 2008 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Nov 19, 2008 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Aug 16, 2013 |
| Freebsd | — | Upgrade erlang-runtime29Upgrade erlangUpgrade erlang-runtime27Upgrade erlang-runtime28 | Aug 7, 2026 | Aug 4, 2026 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Nov 19, 2008 |
| Nutanix Ahv | — | Upgrade Nutanix AHV to the latest version | Jun 5, 2026 | Sep 4, 2023 |
| Oracle_linux | — | Upgrade openssh-askpassUpgrade openssh-serverUpgrade openssh-clientsUpgrade openssh | Oct 16, 2024 | Nov 19, 2008 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub