İçeriğe atla
Noroxi

CWE-322 · 19 kayıt

Key Exchange without Entity Authentication

Bu sınıftaki CVE’ler

19 kayıt

  • CVE-2026-1709
    41Planlayın

    Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication

    KritikCVSS 9,8İstismar yokEPSS %6

    keylime · keylime6 Şub 2026

  • CVE-2026-89422
    37İzleyin

    TLS 1.3 client skips server authentication when ServerHello carries an unsolicited pre_shared_key extension

    KritikCVSS 9,3İstismar yokEPSS %1

    erlang · otp22 Eyl 2026

  • Duplicate Advisory: Keylime Missing Authentication for Critical Function and Improper Authentication

    KritikCVSS 9,4İstismar yok

    PyPI · keylime6 Şub 2026

  • CVE-2026-11745
    35İzleyin

    A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not ver

    YüksekCVSS 8,8İstismar yokEPSS %0

    ly corporation · central dogma21 Haz 2026

  • CVE-2025-20163
    34İzleyin

    Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability

    YüksekCVSS 8,7İstismar yokEPSS %0

    cisco · nexus dashboard4 Haz 2025

  • CVE-2026-45361
    32İzleyin

    Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)

    YüksekCVSS 8,1İstismar yokEPSS %1

    apache · apache-airflow-providers-google25 May 2026

  • CVE-2026-58065
    32İzleyin

    Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification

    YüksekCVSS 8,1İstismar yokEPSS %1

    apache · apache-airflow-providers-git13 Tem 2026

  • CVE-2021-34433
    30İzleyin

    In Eclipse Californium version 2.0.0 to 2.6.4 and 3.0.0-M1 to 3.0.0-M3, the certificate based (x509 and RPK) DTLS handshakes accidentally su

    YüksekCVSS 7,5İstismar yokEPSS %0

    eclipse · californium20 Ağu 2021

  • CVE-2025-62501
    28İzleyin

    SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53

    YüksekCVSS 7,0İstismar yokEPSS %0

    tp-link · archer ax53 firmware3 Şub 2026

  • CVE-2024-47519
    28İzleyin

    Backup uploads to ETM subject to man-in-the-middle interception

    YüksekCVSS 7,1İstismar yokEPSS %0

    arista · ng firewall10 Oca 2025

  • CVE-2025-13914
    28İzleyin

    Apstra: SSH host key validation vulnerability for managed devices

    YüksekCVSS 7,0İstismar yokEPSS %0

    juniper · apstra9 Nis 2026

  • CVE-2024-7516
    28İzleyin

    Brocade Fabric OS before 9.2.2 does not enforce strict host key checking

    YüksekCVSS 7,0İstismar yokEPSS %0

    broadcom · fabric operating system12 Kas 2024

  • CVE-2024-4871
    27İzleyin

    Foreman: host ssh key not being checked in remote execution

    OrtaCVSS 6,8İstismar yokEPSS %1

    red hat · red hat satellite 6.15 for rhel 814 May 2024

  • CVE-2026-18654
    27İzleyin

    Disabled SSH host key verification in Amazon AWS CLI EMR helper commands

    OrtaCVSS 6,9İstismar yokEPSS %0

    aws · aws-cli3 Ağu 2026

  • CVE-2024-6572
    25İzleyin

    Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem'

    OrtaCVSS 6,3İstismar yokEPSS %0

    checkmk · checkmk9 Eyl 2024

  • CVE-2026-33697
    25İzleyin

    CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys

    OrtaCVSS 6,3Kavram kanıtıEPSS %0

    ultraviolet · cocos ai26 Mar 2026

  • CVE-2026-77703
    23İzleyin

    SSH Host Key Verification Bypass in HAVELSAN's Liman Render Engine

    OrtaCVSS 5,9İstismar yokEPSS %0

    havelsan inc. · liman render engine5 gün önce

  • CVE-2026-1354
    23İzleyin

    Zero Motorcycles Firmware Key Exchange without Entity Authentication

    OrtaCVSS 5,9İstismar yokEPSS %0

    zero motorcycles · zero motorcycles firmware21 Nis 2026

  • CVE-2025-10966
    17İzleyin

    missing SFTP host verification with wolfSSH

    OrtaCVSS 4,3İstismar yokEPSS %0

    haxx · curl7 Kas 2025

Tüm zafiyet sınıfları