Skip to content
Noroxi

CWE-322 · 19 records

Key Exchange without Entity Authentication

CVEs in this class

19 records

  • Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication

    CriticalCVSS 9.8No exploitEPSS 6%

    keylime · keylimeFeb 6, 2026

  • TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension

    CriticalCVSS 9.3No exploitEPSS 1%

    erlang · otpSep 22, 2026

  • Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication

    CriticalCVSS 9.4No exploit

    PyPI · keylimeFeb 6, 2026

  • A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver

    HighCVSS 8.8No exploitEPSS 0%

    ly corporation · central dogmaJun 21, 2026

  • Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability

    HighCVSS 8.7No exploitEPSS 0%

    cisco · nexus dashboardJun 4, 2025

  • Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)

    HighCVSS 8.1No exploitEPSS 1%

    apache · apache-airflow-providers-googleMay 25, 2026

  • Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification

    HighCVSS 8.1No exploitEPSS 1%

    apache · apache-airflow-providers-gitJul 13, 2026

  • In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su

    HighCVSS 7.5No exploitEPSS 0%

    eclipse · californiumAug 20, 2021

  • SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53

    HighCVSS 7.0No exploitEPSS 0%

    tp-link · archer ax53 firmwareFeb 3, 2026

  • Backup uploads to ETM subject to man-in-the-middle interception

    HighCVSS 7.1No exploitEPSS 0%

    arista · ng firewallJan 10, 2025

  • Apstra: SSH host key validation vulnerability for managed devices

    HighCVSS 7.0No exploitEPSS 0%

    juniper · apstraApr 9, 2026

  • CVE-2024-7516
    28Monitor

    Brocade Fabric OS before 9.2.2 does not enforce strict host key checking

    HighCVSS 7.0No exploitEPSS 0%

    broadcom · fabric operating systemNov 12, 2024

  • CVE-2024-4871
    27Monitor

    Foreman: host ssh key not being checked in remote execution

    MediumCVSS 6.8No exploitEPSS 1%

    red hat · red hat satellite 6.15 for rhel 8May 14, 2024

  • Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

    MediumCVSS 6.9No exploitEPSS 0%

    aws · aws-cliAug 3, 2026

  • CVE-2024-6572
    25Monitor

    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'

    MediumCVSS 6.3No exploitEPSS 0%

    checkmk · checkmkSep 9, 2024

  • CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys

    MediumCVSS 6.3Proof of conceptEPSS 0%

    ultraviolet · cocos aiMar 26, 2026

  • SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine

    MediumCVSS 5.9No exploitEPSS 0%

    havelsan inc. · liman render engine6 days ago

  • CVE-2026-1354
    23Monitor

    Zero Motorcycles Firmware Key Exchange without Entity Authentication

    MediumCVSS 5.9No exploitEPSS 0%

    zero motorcycles · zero motorcycles firmwareApr 21, 2026

  • missing SFTP host verification with wolfSSH

    MediumCVSS 4.3No exploitEPSS 0%

    haxx · curlNov 7, 2025

All vulnerability classes