CVE-2024-39223

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey
Configurations

No configuration.

History

09 Jul 2024, 16:22

Type Values Removed Values Added
CWE CWE-289
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

05 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) Una omisión de autenticación en el servicio SSH de gost v2.11.5 permite a los atacantes interceptar las comunicaciones configurando la función HostKeyCallback en ssh.InsecureIgnoreHostKey

03 Jul 2024, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-03 15:15

Updated : 2024-07-09 16:22


NVD link : CVE-2024-39223

Mitre link : CVE-2024-39223

CVE.ORG link : CVE-2024-39223


JSON object : View

Products Affected

No product.

CWE
CWE-289

Authentication Bypass by Alternate Name