PT-2025-22345 · Openssh · Openssh

Published

2025-05-21

·

Updated

2025-12-27

·

CVE-2025-48416

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions OpenSSH (affected versions not specified)
Description The issue concerns an OpenSSH daemon listening on TCP port 22, with a hard-coded entry in the "/etc/shadow" file for the "root" user. Although the default SSH configuration has "PermitRootLogin" disabled, preventing root user login via SSH, this configuration can be bypassed or changed by an attacker through multiple paths.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Hidden Functionality

Weakness Enumeration

Related Identifiers

CVE-2025-48416

Affected Products

Openssh