The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssh | Aug 30, 2017 | Mar 27, 2014 |
| Debian | — | Upgrade openssh | Jul 30, 2024 | Mar 27, 2014 |
| F5 Big Ip | — | Update F5 BIG-IP to the latest version | Jun 17, 2026 | Sep 17, 2015 |
| Hpux | — | Update Secure_Shell.SECURE_SHELL to the latest versionUpdate Secure_Shell.SECSH-CMN to the latest version | Aug 11, 2017 | Mar 27, 2014 |
| Ibm Aix | — | Apply the fix or workaround for openssh_advisory4 | Nov 30, 2017 | Mar 27, 2014 |
| Openbsd Openssh | — | Upgrade to the latest version of OpenSSH | Mar 31, 2014 | Mar 27, 2014 |
| Oracle Solaris | — | Upgrade entire to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3 | May 29, 2017 | Mar 27, 2014 |
| Oracle_linux | — | Upgrade openssh-serverUpgrade openssh-ldapUpgrade openssh-server-sysvinitUpgrade openssh-clientsUpgrade openssh-keycatUpgrade openssh-askpassUpgrade pam_ssh_agent_authUpgrade openssh | Oct 16, 2024 | Mar 27, 2014 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Mar 24, 2014 |
| Suse | — | Upgrade opensshUpgrade openssh-fipsUpgrade openssh-openssl1-helpersUpgrade openssh-helpersUpgrade openssh-openssl1 | Dec 18, 2015 | Mar 27, 2014 |
| Ubuntu | — | Upgrade openssh-client | Nov 8, 2024 | Mar 27, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub