← Zuruck zu CVEs
CVE-2024-39223
CRITICAL9.8
Beschreibung
An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
CVE Details
CVSS v3.1 Bewertung9.8
SchweregradCRITICAL
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht7/3/2024
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Schwachen (CWE)
CWE-639
Referenzen
https://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229(cve@mitre.org)
https://github.com/ginuerzh/gost/issues/1034(cve@mitre.org)
https://gist.github.com/nyxfqq/a7242170b1118e78436a62dee4e09e8a(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/ginuerzh/gost/blob/729d0e70005607dc7c69fc1de62fd8fe21f85355/ssh.go#L229(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/ginuerzh/gost/issues/1034(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.