Записи asyncssh project
5 опубликованных записей вендора asyncssh project.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
5 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Средняя5,9 | — | 93,5 % | 18 дек. 2023 г. |
40В плане | CVE-2018-7749Эксплойта нет | The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other asyncssh project · asyncssh · CWE-287 | Критическая9,8 | — | 1,7 % | 12 мар. 2018 г. |
32Наблюдать | CVE-2026-45309Эксплойта нет | AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal usernameasyncssh project · asyncssh · CWE-22 | Высокая8,2 | — | 0,6 % | 17 июл. 2026 г. |
27Наблюдать | CVE-2023-46446Эксплойта нет | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shelasyncssh project · asyncssh · CWE-639 | Средняя6,8 | — | 0,9 % | 13 нояб. 2023 г. |
23Наблюдать | CVE-2023-46445Эксплойта нет | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "asyncssh project · asyncssh · CWE-345 | Средняя5,9 | — | 0,6 % | 13 нояб. 2023 г. |
- CVE-2023-4879551В плане
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
СредняяCVSS 5,9Proof of conceptEPSS 94 %ssh · ssh18 дек. 2023 г.
- CVE-2018-774940В плане
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %asyncssh project · asyncssh12 мар. 2018 г.
- CVE-2026-4530932Наблюдать
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %asyncssh project · asyncssh17 июл. 2026 г.
- CVE-2023-4644627Наблюдать
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shel
СредняяCVSS 6,8Эксплойта нетEPSS 1 %asyncssh project · asyncssh13 нояб. 2023 г.
- CVE-2023-4644523Наблюдать
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "
СредняяCVSS 5,9Эксплойта нетEPSS 1 %asyncssh project · asyncssh13 нояб. 2023 г.