CWE-322 · 19 записей
Key Exchange without Entity Authentication
CVE этого класса
19 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2026-1709Эксплойта нет | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Критическая9,8 | — | 5,5 % | 6 февр. 2026 г. |
37Наблюдать | CVE-2026-89422Эксплойта нет | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extensionerlang · otp · CWE-322 | Критическая9,3 | — | 0,6 % | 22 сент. 2026 г. |
37Наблюдать | GHSA-27jc-jmp8-qfw5Эксплойта нет | Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper AuthenticationPyPI · keylime · CWE-322 | Критическая9,4 | — | — | 6 февр. 2026 г. |
35Наблюдать | CVE-2026-11745Эксплойта нет | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verly corporation · central dogma · CWE-322 | Высокая8,8 | — | 0,2 % | 21 июн. 2026 г. |
34Наблюдать | CVE-2025-20163Эксплойта нет | Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerabilitycisco · nexus dashboard · CWE-322 | Высокая8,7 | — | 0,4 % | 4 июн. 2025 г. |
32Наблюдать | CVE-2026-45361Эксплойта нет | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | Высокая8,1 | — | 0,8 % | 25 мая 2026 г. |
32Наблюдать | CVE-2026-58065Эксплойта нет | Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verificationapache · apache-airflow-providers-git · CWE-322 | Высокая8,1 | — | 0,7 % | 13 июл. 2026 г. |
30Наблюдать | CVE-2021-34433Эксплойта нет | In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally sueclipse · californium · CWE-322 | Высокая7,5 | — | 0,3 % | 20 авг. 2021 г. |
28Наблюдать | CVE-2025-62501Эксплойта нет | SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53tp-link · archer ax53 firmware · CWE-322 | Высокая7,0 | — | 0,5 % | 3 февр. 2026 г. |
28Наблюдать | CVE-2024-47519Эксплойта нет | Backup uploads to ETM subject to man-in-the-middle interceptionarista · ng firewall · CWE-322 | Высокая7,1 | — | 0,3 % | 10 янв. 2025 г. |
28Наблюдать | CVE-2025-13914Эксплойта нет | Apstra: SSH host key validation vulnerability for managed devicesjuniper · apstra · CWE-322 | Высокая7,0 | — | 0,3 % | 9 апр. 2026 г. |
28Наблюдать | CVE-2024-7516Эксплойта нет | Brocade Fabric OS before 9.2.2 does not enforce strict host key checkingbroadcom · fabric operating system · CWE-322 | Высокая7,0 | — | 0,3 % | 12 нояб. 2024 г. |
27Наблюдать | CVE-2024-4871Эксплойта нет | Foreman: host ssh key not being checked in remote executionred hat · red hat satellite 6.15 for rhel 8 · CWE-322 | Средняя6,8 | — | 0,6 % | 14 мая 2024 г. |
27Наблюдать | CVE-2026-18654Эксплойта нет | Disabled SSH host key verification in Amazon AWS CLI EMR helper commandsaws · aws-cli · CWE-322 | Средняя6,9 | — | 0,3 % | 3 авг. 2026 г. |
25Наблюдать | CVE-2024-6572Эксплойта нет | Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'checkmk · checkmk · CWE-322 | Средняя6,3 | — | 0,3 % | 9 сент. 2024 г. |
25Наблюдать | CVE-2026-33697Proof of concept | CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keysultraviolet · cocos ai · CWE-322 | Средняя6,3 | — | 0,1 % | 26 мар. 2026 г. |
23Наблюдать | CVE-2026-77703Эксплойта нет | SSH Host Key Verification Bypass in HAVELSAN's Liman Render Enginehavelsan inc. · liman render engine · CWE-322 | Средняя5,9 | — | 0,2 % | 6 дней назад |
23Наблюдать | CVE-2026-1354Эксплойта нет | Zero Motorcycles Firmware Key Exchange without Entity Authenticationzero motorcycles · zero motorcycles firmware · CWE-322 | Средняя5,9 | — | 0,1 % | 21 апр. 2026 г. |
17Наблюдать | CVE-2025-10966Эксплойта нет | missing SFTP host verification with wolfSSHhaxx · curl · CWE-322 | Средняя4,3 | — | 0,4 % | 7 нояб. 2025 г. |
- CVE-2026-170941В плане
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %keylime · keylime6 февр. 2026 г.
- CVE-2026-8942237Наблюдать
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %erlang · otp22 сент. 2026 г.
- GHSA-27jc-jmp8-qfw537Наблюдать
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
КритическаяCVSS 9,4Эксплойта нетPyPI · keylime6 февр. 2026 г.
- CVE-2026-1174535Наблюдать
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %ly corporation · central dogma21 июн. 2026 г.
- CVE-2025-2016334Наблюдать
Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %cisco · nexus dashboard4 июн. 2025 г.
- CVE-2026-4536132Наблюдать
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apache · apache-airflow-providers-google25 мая 2026 г.
- CVE-2026-5806532Наблюдать
Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %apache · apache-airflow-providers-git13 июл. 2026 г.
- CVE-2021-3443330Наблюдать
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su
ВысокаяCVSS 7,5Эксплойта нетEPSS 0 %eclipse · californium20 авг. 2021 г.
- CVE-2025-6250128Наблюдать
SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %tp-link · archer ax53 firmware3 февр. 2026 г.
- CVE-2024-4751928Наблюдать
Backup uploads to ETM subject to man-in-the-middle interception
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %arista · ng firewall10 янв. 2025 г.
- CVE-2025-1391428Наблюдать
Apstra: SSH host key validation vulnerability for managed devices
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %juniper · apstra9 апр. 2026 г.
- CVE-2024-751628Наблюдать
Brocade Fabric OS before 9.2.2 does not enforce strict host key checking
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %broadcom · fabric operating system12 нояб. 2024 г.
- CVE-2024-487127Наблюдать
Foreman: host ssh key not being checked in remote execution
СредняяCVSS 6,8Эксплойта нетEPSS 1 %red hat · red hat satellite 6.15 for rhel 814 мая 2024 г.
- CVE-2026-1865427Наблюдать
Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
СредняяCVSS 6,9Эксплойта нетEPSS 0 %aws · aws-cli3 авг. 2026 г.
- CVE-2024-657225Наблюдать
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
СредняяCVSS 6,3Эксплойта нетEPSS 0 %checkmk · checkmk9 сент. 2024 г.
- CVE-2026-3369725Наблюдать
CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
СредняяCVSS 6,3Proof of conceptEPSS 0 %ultraviolet · cocos ai26 мар. 2026 г.
- CVE-2026-7770323Наблюдать
SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
СредняяCVSS 5,9Эксплойта нетEPSS 0 %havelsan inc. · liman render engine6 дней назад
- CVE-2026-135423Наблюдать
Zero Motorcycles Firmware Key Exchange without Entity Authentication
СредняяCVSS 5,9Эксплойта нетEPSS 0 %zero motorcycles · zero motorcycles firmware21 апр. 2026 г.
- CVE-2025-1096617Наблюдать
missing SFTP host verification with wolfSSH
СредняяCVSS 4,3Эксплойта нетEPSS 0 %haxx · curl7 нояб. 2025 г.