Перейти к содержимому
Noroxi

CWE-322 · 19 записей

Key Exchange without Entity Authentication

CVE этого класса

19 записей

  • CVE-2026-1709
    41В плане

    Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication

    КритическаяCVSS 9,8Эксплойта нетEPSS 6 %

    keylime · keylime6 февр. 2026 г.

  • CVE-2026-89422
    37Наблюдать

    TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension

    КритическаяCVSS 9,3Эксплойта нетEPSS 1 %

    erlang · otp22 сент. 2026 г.

  • GHSA-27jc-jmp8-qfw5
    37Наблюдать

    Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication

    КритическаяCVSS 9,4Эксплойта нет

    PyPI · keylime6 февр. 2026 г.

  • CVE-2026-11745
    35Наблюдать

    A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    ly corporation · central dogma21 июн. 2026 г.

  • CVE-2025-20163
    34Наблюдать

    Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability

    ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %

    cisco · nexus dashboard4 июн. 2025 г.

  • CVE-2026-45361
    32Наблюдать

    Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    apache · apache-airflow-providers-google25 мая 2026 г.

  • CVE-2026-58065
    32Наблюдать

    Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    apache · apache-airflow-providers-git13 июл. 2026 г.

  • CVE-2021-34433
    30Наблюдать

    In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su

    ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %

    eclipse · californium20 авг. 2021 г.

  • CVE-2025-62501
    28Наблюдать

    SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    tp-link · archer ax53 firmware3 февр. 2026 г.

  • CVE-2024-47519
    28Наблюдать

    Backup uploads to ETM subject to man-in-the-middle interception

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    arista · ng firewall10 янв. 2025 г.

  • CVE-2025-13914
    28Наблюдать

    Apstra: SSH host key validation vulnerability for managed devices

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    juniper · apstra9 апр. 2026 г.

  • CVE-2024-7516
    28Наблюдать

    Brocade Fabric OS before 9.2.2 does not enforce strict host key checking

    ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %

    broadcom · fabric operating system12 нояб. 2024 г.

  • CVE-2024-4871
    27Наблюдать

    Foreman: host ssh key not being checked in remote execution

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    red hat · red hat satellite 6.15 for rhel 814 мая 2024 г.

  • CVE-2026-18654
    27Наблюдать

    Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    aws · aws-cli3 авг. 2026 г.

  • CVE-2024-6572
    25Наблюдать

    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'

    СредняяCVSS 6,3Эксплойта нетEPSS 0 %

    checkmk · checkmk9 сент. 2024 г.

  • CVE-2026-33697
    25Наблюдать

    CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys

    СредняяCVSS 6,3Proof of conceptEPSS 0 %

    ultraviolet · cocos ai26 мар. 2026 г.

  • CVE-2026-77703
    23Наблюдать

    SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    havelsan inc. · liman render engine6 дней назад

  • CVE-2026-1354
    23Наблюдать

    Zero Motorcycles Firmware Key Exchange without Entity Authentication

    СредняяCVSS 5,9Эксплойта нетEPSS 0 %

    zero motorcycles · zero motorcycles firmware21 апр. 2026 г.

  • CVE-2025-10966
    17Наблюдать

    missing SFTP host verification with wolfSSH

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    haxx · curl7 нояб. 2025 г.

Все классы уязвимостей