asyncssh project records
5 published records for vendor asyncssh project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-345 Insufficient Verification of Data Authenticity1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
40Plan | CVE-2018-7749No exploit | The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other asyncssh project · asyncssh · CWE-287 | Critical9.8 | — | 1.7% | Mar 12, 2018 |
32Monitor | CVE-2026-45309No exploit | AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal usernameasyncssh project · asyncssh · CWE-22 | High8.2 | — | 0.6% | Jul 17, 2026 |
27Monitor | CVE-2023-46446No exploit | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shelasyncssh project · asyncssh · CWE-639 | Medium6.8 | — | 0.9% | Nov 13, 2023 |
23Monitor | CVE-2023-46445No exploit | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "asyncssh project · asyncssh · CWE-345 | Medium5.9 | — | 0.6% | Nov 13, 2023 |
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2018-774940Plan
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other
CriticalCVSS 9.8No exploitEPSS 2%asyncssh project · asyncsshMar 12, 2018
- CVE-2026-4530932Monitor
AsyncSSH `AuthorizedKeysFile %u` path traversal allows attacker-selected authorized keys to authenticate a traversal username
HighCVSS 8.2No exploitEPSS 1%asyncssh project · asyncsshJul 17, 2026
- CVE-2023-4644627Monitor
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shel
MediumCVSS 6.8No exploitEPSS 1%asyncssh project · asyncsshNov 13, 2023
- CVE-2023-4644523Monitor
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "
MediumCVSS 5.9No exploitEPSS 1%asyncssh project · asyncsshNov 13, 2023