PT-2024-28396 · Gost+1 · Gost+1
Sy2339226
·
Published
2024-07-03
·
Updated
2024-11-05
·
CVE-2024-39223
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
gost version 2.11.5
Description
An authentication bypass in the SSH service allows attackers to intercept communications by setting the
HostKeyCallback function to ssh.InsecureIgnoreHostKey. This issue is related to missing key verification in gost.Recommendations
For gost version 2.11.5, consider disabling the SSH service until a patch is available. As a temporary workaround, avoid setting the
HostKeyCallback function to ssh.InsecureIgnoreHostKey to prevent authentication bypass. Restrict access to the SSH service to minimize the risk of exploitation.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Suse
Gost