OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apple Osx Openssh | — | Upgrade macOS to the latest version | Oct 31, 2024 | Sep 16, 2024 |
| Aruba Aos Cx | — | HPE Aruba Networking ArubaOS-CX Switches
- ArubaOS-CX 10.16.xxxx: 10.16.1010 and above
- ArubaOS-CX 10.15.xxxx: 10.15.1010 and above
- ArubaOS-CX 10.13.xxxx: 10.13.1090 and above
- ArubaOS-CX 10.10.xxxx: 10.10.1160 and above
Software versions with resolution/fixes for the Vulnerability covered above can be downloaded
from the HPE Networking Support Portal at https://networkingsupport.hpe.com/home/
HPE Aruba Networking does not evaluate or patch software branches that have reached their End of Maintenance (EoM) milestone. For more information about HPE Aruba Networking
End of Life policy please visit: https://www.hpe.com/psnow/doc/a00143052enw
| Jun 3, 2026 | Jun 2, 2026 |
| Debian | — | Upgrade openssh | Jul 27, 2026 | Jul 27, 2026 |
| Freebsd | — | Upgrade FreeBSD | Jan 31, 2025 | Jan 30, 2025 |
| Suse | — | Upgrade openssh-fipsUpgrade openssh-cavsUpgrade openssh-server-config-rootloginUpgrade opensshUpgrade openssh-commonUpgrade openssh-serverUpgrade openssh-helpersUpgrade openssh-clientsUpgrade openssh-askpass-gnomeUpgrade openssh-server-config-disallow-rootlogin | Jul 11, 2024 | Jul 2, 2024 |
| Ubuntu | — | Upgrade openssh-serverUpgrade openssh-client | Jul 10, 2024 | Jul 2, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub