PT-2026-1497 · Wolfssh · Wolfssh
Olivier Levillain
·
Publicado
2026-01-06
·
Atualizado
2026-01-06
·
CVE-2025-14942
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSH versions 1.4.21 and earlier
Description
The wolfSSH key exchange state machine can be manipulated, potentially leading to the exposure of the client’s password in plaintext. This manipulation could also allow an attacker to trick the client into sending a fraudulent signature or bypassing user authentication altogether. The issue affects both client and server applications utilizing wolfSSH.
Recommendations
Update to a newer version of wolfSSH or apply the available fix patch.
It is recommended to update credentials used with wolfSSH.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wolfssh