CWE-322 · 19 records
Key Exchange without Entity Authentication
CVEs in this class
19 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2026-1709No exploit | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Critical9.8 | — | 5.5% | Feb 6, 2026 |
37Monitor | CVE-2026-89422No exploit | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extensionerlang · otp · CWE-322 | Critical9.3 | — | 0.6% | Sep 22, 2026 |
37Monitor | GHSA-27jc-jmp8-qfw5No exploit | Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper AuthenticationPyPI · keylime · CWE-322 | Critical9.4 | — | — | Feb 6, 2026 |
35Monitor | CVE-2026-11745No exploit | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verly corporation · central dogma · CWE-322 | High8.8 | — | 0.2% | Jun 21, 2026 |
34Monitor | CVE-2025-20163No exploit | Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerabilitycisco · nexus dashboard · CWE-322 | High8.7 | — | 0.4% | Jun 4, 2025 |
32Monitor | CVE-2026-45361No exploit | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | High8.1 | — | 0.8% | May 25, 2026 |
32Monitor | CVE-2026-58065No exploit | Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verificationapache · apache-airflow-providers-git · CWE-322 | High8.1 | — | 0.7% | Jul 13, 2026 |
30Monitor | CVE-2021-34433No exploit | In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally sueclipse · californium · CWE-322 | High7.5 | — | 0.3% | Aug 20, 2021 |
28Monitor | CVE-2025-62501No exploit | SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53tp-link · archer ax53 firmware · CWE-322 | High7.0 | — | 0.5% | Feb 3, 2026 |
28Monitor | CVE-2024-47519No exploit | Backup uploads to ETM subject to man-in-the-middle interceptionarista · ng firewall · CWE-322 | High7.1 | — | 0.3% | Jan 10, 2025 |
28Monitor | CVE-2025-13914No exploit | Apstra: SSH host key validation vulnerability for managed devicesjuniper · apstra · CWE-322 | High7.0 | — | 0.3% | Apr 9, 2026 |
28Monitor | CVE-2024-7516No exploit | Brocade Fabric OS before 9.2.2 does not enforce strict host key checkingbroadcom · fabric operating system · CWE-322 | High7.0 | — | 0.3% | Nov 12, 2024 |
27Monitor | CVE-2024-4871No exploit | Foreman: host ssh key not being checked in remote executionred hat · red hat satellite 6.15 for rhel 8 · CWE-322 | Medium6.8 | — | 0.6% | May 14, 2024 |
27Monitor | CVE-2026-18654No exploit | Disabled SSH host key verification in Amazon AWS CLI EMR helper commandsaws · aws-cli · CWE-322 | Medium6.9 | — | 0.3% | Aug 3, 2026 |
25Monitor | CVE-2024-6572No exploit | Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'checkmk · checkmk · CWE-322 | Medium6.3 | — | 0.3% | Sep 9, 2024 |
25Monitor | CVE-2026-33697Proof of concept | CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keysultraviolet · cocos ai · CWE-322 | Medium6.3 | — | 0.1% | Mar 26, 2026 |
23Monitor | CVE-2026-77703No exploit | SSH Host Key Verification Bypass in HAVELSAN's Liman Render Enginehavelsan inc. · liman render engine · CWE-322 | Medium5.9 | — | 0.2% | 6 days ago |
23Monitor | CVE-2026-1354No exploit | Zero Motorcycles Firmware Key Exchange without Entity Authenticationzero motorcycles · zero motorcycles firmware · CWE-322 | Medium5.9 | — | 0.1% | Apr 21, 2026 |
17Monitor | CVE-2025-10966No exploit | missing SFTP host verification with wolfSSHhaxx · curl · CWE-322 | Medium4.3 | — | 0.4% | Nov 7, 2025 |
- CVE-2026-170941Plan
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
CriticalCVSS 9.8No exploitEPSS 6%keylime · keylimeFeb 6, 2026
- CVE-2026-8942237Monitor
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
CriticalCVSS 9.3No exploitEPSS 1%erlang · otpSep 22, 2026
- GHSA-27jc-jmp8-qfw537Monitor
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
CriticalCVSS 9.4No exploitPyPI · keylimeFeb 6, 2026
- CVE-2026-1174535Monitor
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver
HighCVSS 8.8No exploitEPSS 0%ly corporation · central dogmaJun 21, 2026
- CVE-2025-2016334Monitor
Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
HighCVSS 8.7No exploitEPSS 0%cisco · nexus dashboardJun 4, 2025
- CVE-2026-4536132Monitor
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
HighCVSS 8.1No exploitEPSS 1%apache · apache-airflow-providers-googleMay 25, 2026
- CVE-2026-5806532Monitor
Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
HighCVSS 8.1No exploitEPSS 1%apache · apache-airflow-providers-gitJul 13, 2026
- CVE-2021-3443330Monitor
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su
HighCVSS 7.5No exploitEPSS 0%eclipse · californiumAug 20, 2021
- CVE-2025-6250128Monitor
SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53
HighCVSS 7.0No exploitEPSS 0%tp-link · archer ax53 firmwareFeb 3, 2026
- CVE-2024-4751928Monitor
Backup uploads to ETM subject to man-in-the-middle interception
HighCVSS 7.1No exploitEPSS 0%arista · ng firewallJan 10, 2025
- CVE-2025-1391428Monitor
Apstra: SSH host key validation vulnerability for managed devices
HighCVSS 7.0No exploitEPSS 0%juniper · apstraApr 9, 2026
- CVE-2024-751628Monitor
Brocade Fabric OS before 9.2.2 does not enforce strict host key checking
HighCVSS 7.0No exploitEPSS 0%broadcom · fabric operating systemNov 12, 2024
- CVE-2024-487127Monitor
Foreman: host ssh key not being checked in remote execution
MediumCVSS 6.8No exploitEPSS 1%red hat · red hat satellite 6.15 for rhel 8May 14, 2024
- CVE-2026-1865427Monitor
Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
MediumCVSS 6.9No exploitEPSS 0%aws · aws-cliAug 3, 2026
- CVE-2024-657225Monitor
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
MediumCVSS 6.3No exploitEPSS 0%checkmk · checkmkSep 9, 2024
- CVE-2026-3369725Monitor
CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
MediumCVSS 6.3Proof of conceptEPSS 0%ultraviolet · cocos aiMar 26, 2026
- CVE-2026-7770323Monitor
SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
MediumCVSS 5.9No exploitEPSS 0%havelsan inc. · liman render engine6 days ago
- CVE-2026-135423Monitor
Zero Motorcycles Firmware Key Exchange without Entity Authentication
MediumCVSS 5.9No exploitEPSS 0%zero motorcycles · zero motorcycles firmwareApr 21, 2026
- CVE-2025-1096617Monitor
missing SFTP host verification with wolfSSH
MediumCVSS 4.3No exploitEPSS 0%haxx · curlNov 7, 2025