SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-25136

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling.

MEDIUM 6.5EPSS 89.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 89.7%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS
89.69% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-415
Affected
openbsd/openssh · fedoraproject/fedora · netapp/ontap select deploy administration utility · netapp/a250 firmware · netapp/500f firmware · netapp/c250 firmware
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.