CWE-322 · 19 kayıt
Key Exchange without Entity Authentication
Bu sınıftaki CVE’ler
19 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2026-1709İstismar yok | Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authenticationkeylime · keylime · CWE-322 | Kritik9,8 | — | %5,5 | 6 Şub 2026 |
37İzleyin | CVE-2026-89422İstismar yok | TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extensionerlang · otp · CWE-322 | Kritik9,3 | — | %0,6 | 22 Eyl 2026 |
37İzleyin | GHSA-27jc-jmp8-qfw5İstismar yok | Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper AuthenticationPyPI · keylime · CWE-322 | Kritik9,4 | — | — | 6 Şub 2026 |
35İzleyin | CVE-2026-11745İstismar yok | A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verly corporation · central dogma · CWE-322 | Yüksek8,8 | — | %0,2 | 21 Haz 2026 |
34İzleyin | CVE-2025-20163İstismar yok | Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerabilitycisco · nexus dashboard · CWE-322 | Yüksek8,7 | — | %0,4 | 4 Haz 2025 |
32İzleyin | CVE-2026-45361İstismar yok | Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)apache · apache-airflow-providers-google · CWE-322 | Yüksek8,1 | — | %0,8 | 25 May 2026 |
32İzleyin | CVE-2026-58065İstismar yok | Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verificationapache · apache-airflow-providers-git · CWE-322 | Yüksek8,1 | — | %0,7 | 13 Tem 2026 |
30İzleyin | CVE-2021-34433İstismar yok | In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally sueclipse · californium · CWE-322 | Yüksek7,5 | — | %0,3 | 20 Ağu 2021 |
28İzleyin | CVE-2025-62501İstismar yok | SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53tp-link · archer ax53 firmware · CWE-322 | Yüksek7,0 | — | %0,5 | 3 Şub 2026 |
28İzleyin | CVE-2024-47519İstismar yok | Backup uploads to ETM subject to man-in-the-middle interceptionarista · ng firewall · CWE-322 | Yüksek7,1 | — | %0,3 | 10 Oca 2025 |
28İzleyin | CVE-2025-13914İstismar yok | Apstra: SSH host key validation vulnerability for managed devicesjuniper · apstra · CWE-322 | Yüksek7,0 | — | %0,3 | 9 Nis 2026 |
28İzleyin | CVE-2024-7516İstismar yok | Brocade Fabric OS before 9.2.2 does not enforce strict host key checkingbroadcom · fabric operating system · CWE-322 | Yüksek7,0 | — | %0,3 | 12 Kas 2024 |
27İzleyin | CVE-2024-4871İstismar yok | Foreman: host ssh key not being checked in remote executionred hat · red hat satellite 6.15 for rhel 8 · CWE-322 | Orta6,8 | — | %0,6 | 14 May 2024 |
27İzleyin | CVE-2026-18654İstismar yok | Disabled SSH host key verification in Amazon AWS CLI EMR helper commandsaws · aws-cli · CWE-322 | Orta6,9 | — | %0,3 | 3 Ağu 2026 |
25İzleyin | CVE-2024-6572İstismar yok | Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'checkmk · checkmk · CWE-322 | Orta6,3 | — | %0,3 | 9 Eyl 2024 |
25İzleyin | CVE-2026-33697Kavram kanıtı | CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keysultraviolet · cocos ai · CWE-322 | Orta6,3 | — | %0,1 | 26 Mar 2026 |
23İzleyin | CVE-2026-77703İstismar yok | SSH Host Key Verification Bypass in HAVELSAN's Liman Render Enginehavelsan inc. · liman render engine · CWE-322 | Orta5,9 | — | %0,2 | 5 gün önce |
23İzleyin | CVE-2026-1354İstismar yok | Zero Motorcycles Firmware Key Exchange without Entity Authenticationzero motorcycles · zero motorcycles firmware · CWE-322 | Orta5,9 | — | %0,1 | 21 Nis 2026 |
17İzleyin | CVE-2025-10966İstismar yok | missing SFTP host verification with wolfSSHhaxx · curl · CWE-322 | Orta4,3 | — | %0,4 | 7 Kas 2025 |
- CVE-2026-170941Planlayın
Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
KritikCVSS 9,8İstismar yokEPSS %6keylime · keylime6 Şub 2026
- CVE-2026-8942237İzleyin
TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension
KritikCVSS 9,3İstismar yokEPSS %1erlang · otp22 Eyl 2026
- GHSA-27jc-jmp8-qfw537İzleyin
Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication
KritikCVSS 9,4İstismar yokPyPI · keylime6 Şub 2026
- CVE-2026-1174535İzleyin
A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver
YüksekCVSS 8,8İstismar yokEPSS %0ly corporation · central dogma21 Haz 2026
- CVE-2025-2016334İzleyin
Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
YüksekCVSS 8,7İstismar yokEPSS %0cisco · nexus dashboard4 Haz 2025
- CVE-2026-4536132İzleyin
Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
YüksekCVSS 8,1İstismar yokEPSS %1apache · apache-airflow-providers-google25 May 2026
- CVE-2026-5806532İzleyin
Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
YüksekCVSS 8,1İstismar yokEPSS %1apache · apache-airflow-providers-git13 Tem 2026
- CVE-2021-3443330İzleyin
In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su
YüksekCVSS 7,5İstismar yokEPSS %0eclipse · californium20 Ağu 2021
- CVE-2025-6250128İzleyin
SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53
YüksekCVSS 7,0İstismar yokEPSS %0tp-link · archer ax53 firmware3 Şub 2026
- CVE-2024-4751928İzleyin
Backup uploads to ETM subject to man-in-the-middle interception
YüksekCVSS 7,1İstismar yokEPSS %0arista · ng firewall10 Oca 2025
- CVE-2025-1391428İzleyin
Apstra: SSH host key validation vulnerability for managed devices
YüksekCVSS 7,0İstismar yokEPSS %0juniper · apstra9 Nis 2026
- CVE-2024-751628İzleyin
Brocade Fabric OS before 9.2.2 does not enforce strict host key checking
YüksekCVSS 7,0İstismar yokEPSS %0broadcom · fabric operating system12 Kas 2024
- CVE-2024-487127İzleyin
Foreman: host ssh key not being checked in remote execution
OrtaCVSS 6,8İstismar yokEPSS %1red hat · red hat satellite 6.15 for rhel 814 May 2024
- CVE-2026-1865427İzleyin
Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
OrtaCVSS 6,9İstismar yokEPSS %0aws · aws-cli3 Ağu 2026
- CVE-2024-657225İzleyin
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'
OrtaCVSS 6,3İstismar yokEPSS %0checkmk · checkmk9 Eyl 2024
- CVE-2026-3369725İzleyin
CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
OrtaCVSS 6,3Kavram kanıtıEPSS %0ultraviolet · cocos ai26 Mar 2026
- CVE-2026-7770323İzleyin
SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine
OrtaCVSS 5,9İstismar yokEPSS %0havelsan inc. · liman render engine5 gün önce
- CVE-2026-135423İzleyin
Zero Motorcycles Firmware Key Exchange without Entity Authentication
OrtaCVSS 5,9İstismar yokEPSS %0zero motorcycles · zero motorcycles firmware21 Nis 2026
- CVE-2025-1096617İzleyin
missing SFTP host verification with wolfSSH
OrtaCVSS 4,3İstismar yokEPSS %0haxx · curl7 Kas 2025