An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
CVSS Details
- CVSS 3.1 Base Score: 6.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-python-asyncssh | Sep 30, 2024 | Nov 14, 2023 | |
| Progress Moveit Transfer | progress-moveit-transfer-disable-weak-ssh-algorithms-terrapin | Nov 27, 2025 | Dec 21, 2023 | |
| Ubuntu | ubuntu-pro-upgrade-python3-asyncsshubuntu-upgrade-python3-asyncssh | Nov 19, 2024 | Nov 14, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub