sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.
CVSS Details
- CVSS 3.1 Base Score: 4.2
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N)
- CVSS 3.0 Base Score: 4.9
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Upgrade macOS to the latest version | Apr 5, 2017 | Mar 18, 2014 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Mar 18, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 17, 2015 |
| Gentoo Linux | — | Upgrade net-misc/openssh. | Oct 30, 2017 | Mar 18, 2014 |
| Hpux | — | Update Secure_Shell.SECSH-CMN to the latest versionUpdate Secure_Shell.SECURE_SHELL to the latest version | Aug 11, 2017 | Mar 18, 2014 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory4 | Nov 30, 2017 | Mar 18, 2014 |
| Openbsd Openssh | — | Upgrade to OpenSSH version 6.6 | Mar 19, 2014 | Mar 18, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | Mar 18, 2014 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-clientsUpgrade opensshUpgrade openssh-askpassUpgrade pam_ssh_agent_auth | Oct 16, 2024 | Mar 18, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 15, 2014 |
| Suse | — | Upgrade openssh-openssl1-helpersUpgrade openssh-openssl1Upgrade openssh-askpass-gnomeUpgrade opensshUpgrade openssh-askpassUpgrade openssh-fips | Dec 18, 2015 | Mar 18, 2014 |
| Ubuntu | — | Upgrade openssh-server | Nov 8, 2024 | Mar 18, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub