by HooangF4t
General
Information
[Link]
Hostnames
[Link]
Domains [Link] [Link]
Cloud Provider Amazon
Cloud Region ap-southeast-1
Cloud Service EC2
Country Singapore
City Singapore
Organization Amazon Technologies Inc.
ISP [Link], Inc.
ASN AS16509
OpenPorts
22 80 443
OpenSSH7.4
SSH-2.0-OpenSSH_7.4
Key type: ssh-rsa
Key:
AAAAB3NzaC1yc2EAAAADAQABAAABAQDHLHunzetp7lHJ5tl7QTcfrZiaf1fXzE4
QbqMjJVmE1HP/
by HooangF4t
uaUA5CBjJa0Ds5miTCZhzK9OeetbyqBSCXImi+bxc3B2Z/Ahpb/
kFOYo4TZ8Pl6TYzTqyS87k4XO
2L6i00NdXgkFGcPfe13wGYQIejcmwK9SQk5dlVh9Le27vx/
7LuzncO4O8MuBj7xLr854fhYiTLck
9eEU0WS3UTucnh9lHiDbr4KOZ+80Q+t1p+O1vkpVD2d6dAfqpz3mgsihSh4WA
V3FRSGq0Hb4X3W+
afVZREXHg86G3PLDp9qOXtkoQSkEXZLIhXL0ABIJ1bK9INjNmCkjDfN08uR2
psZjVfIx
Fingerprint: 81:c8:9e:8b:b0:f0:eb:18:c8:1d:6f:79:32:1b:05:48
Kex Algorithms:
curve25519-sha256
curve25519-sha256@[Link]
ecdh-sha2-nistp256
ecdh-sha2-nistp384
ecdh-sha2-nistp521
diffie-hellman-group-exchange-sha256
diffie-hellman-group16-sha512
diffie-hellman-group18-sha512
diffie-hellman-group-exchange-sha1
diffie-hellman-group14-sha256
diffie-hellman-group14-sha1
diffie-hellman-group1-sha1
Server Host Key Algorithms:
ssh-rsa
rsa-sha2-512
rsa-sha2-256
ecdsa-sha2-nistp256
ssh-ed25519
Encryption Algorithms:
by HooangF4t
chacha20-poly1305@[Link]
aes128-ctr
aes192-ctr
aes256-ctr
aes128-gcm@[Link]
aes256-gcm@[Link]
aes128-cbc
aes192-cbc
aes256-cbc
blowfish-cbc
cast128-cbc
3des-cbc
MAC Algorithms:
umac-64-etm@[Link]
umac-128-etm@[Link]
hmac-sha2-256-etm@[Link]
hmac-sha2-512-etm@[Link]
hmac-sha1-etm@[Link]
umac-64@[Link]
umac-128@[Link]
hmac-sha2-256
hmac-sha2-512
hmac-sha1
Compression Algorithms:
none
zlib@[Link]
Vulnerabilities
Latest
by HooangF4t
Note: the device may not be impacted by all of these issues. The vulnerabilities are
implied based on the software and version.
2023
CVE-2023-51767
falseOpenSSH through 9.6, when common types of DRAM are used, might allow
row hammer attacks (for authentication bypass) because the integer value of
authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE:
this is applicable to a certain threat model of attacker-victim co-location in which the
attacker has user privileges.
CVE-2023-51385
falseIn ssh in OpenSSH before 9.6, OS command injection might occur if a user
name or host name has shell metacharacters, and this name is referenced by an expansion
token in certain situations. For example, an untrusted Git repository can have a
submodule with shell metacharacters in a user name or host name.
CVE-2023-48795
falseThe SSH transport protocol with certain OpenSSH extensions, found in
OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity
checks such that some packets are omitted (from the extension negotiation message), and
a client and server may consequently end up with a connection for which some security
features have been downgraded or disabled, aka a Terrapin attack. This occurs because
the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the
handshake phase and mishandles use of sequence numbers. For example, there is an
effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-
MAC). The bypass occurs in chacha20-poly1305@[Link] and (if CBC is used) the
-etm@[Link] MAC algorithms. This also affects Maverick Synergy Java SSH API
before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP,
PuTTY before 0.80, AsyncSSH before 2.14.2, [Link]/x/crypto before 0.17.0, libssh
before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera
Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6,
Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH
through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before
2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH
library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH
through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before
3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5
before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise
SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through [Link], the
net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for [Link], the
thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
by HooangF4t
CVE-2023-38408
falseThe PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an
insufficiently trustworthy search path, leading to remote code execution if an agent is
forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for
loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-
2016-10009.
2021
CVE-2021-41617
4.4sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
configurations are used, allows privilege escalation because supplemental groups are not
initialized as expected. Helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand may run with privileges associated with group
memberships of the sshd process, if the configuration specifies running the command as a
different user.
CVE-2021-36368
2.6An issue was discovered in OpenSSH before 8.9. If a client is using public-key
authentication with agent forwarding but without -oLogLevel=verbose, and an attacker
has silently modified the server to support the None authentication option, then the user
cannot determine whether FIDO authentication is going to confirm that the user wishes to
connect to that server, or that the user wishes to allow that server to connect to a different
server on the user's behalf. NOTE: the vendor's position is "this is not an authentication
bypass, since nothing is being bypassed.
2020
CVE-2020-15778
6.8scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote
function, as demonstrated by backtick characters in the destination argument. NOTE: the
vendor reportedly has stated that they intentionally omit validation of "anomalous
argument transfers" because that could "stand a great chance of breaking existing
workflows."
CVE-2020-14145
4.3The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy
leading to an information leak in the algorithm negotiation. This allows man-in-the-
middle attackers to target initial connection attempts (where no host key for the server
has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also
affected.
2019
CVE-2019-6111
by HooangF4t
5.8An issue was discovered in OpenSSH 7.9. Due to the scp implementation being
derived from 1983 rcp, the server chooses which files/directories are sent to the client.
However, the scp client only performs cursory validation of the object name returned
(only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-
Middle attacker) can overwrite arbitrary files in the scp client target directory. If
recursive operation (-r) is performed, the server can manipulate subdirectories as well (for
example, to overwrite the .ssh/authorized_keys file).
CVE-2019-6110
4.0In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the
server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client
output, for example to use ANSI control codes to hide additional files being transferred.
CVE-2019-6109
4.0An issue was discovered in OpenSSH 7.9. Due to missing character encoding in
the progress display, a malicious server (or Man-in-The-Middle attacker) can employ
crafted object names to manipulate the client output, e.g., by using ANSI control codes to
hide additional files being transferred. This affects refresh_progress_meter() in
progressmeter.c.
2018
CVE-2018-20685
2.6In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass
intended access restrictions via the filename of . or an empty filename. The impact is
modifying the permissions of the target directory on the client side.
CVE-2018-15919
5.0Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be
used by remote attackers to detect existence of users on a target system when GSS2 is in
use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not
want to treat such a username enumeration (or "oracle") as a vulnerability.'
CVE-2018-15473
5.0OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not
delaying bailout for an invalid authenticating user until after the packet containing the
request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-
pubkey.c.
2017
CVE-2017-15906
5.0The process_open function in sftp-server.c in OpenSSH before 7.6 does not
properly prevent write operations in readonly mode, which allows attackers to create
zero-length files.
by HooangF4t
2016
CVE-2016-20012
4.3OpenSSH through 8.7 allows remote attackers, who have a suspicion that a
certain combination of username and public key is known to an SSH server, to test
whether this suspicion is correct. This occurs because a challenge is sent only when that
combination could be valid for a login session. NOTE: the vendor does not recognize
user enumeration as a vulnerability for this product
2008
CVE-2008-3844
9.3Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as
signed in August 2008 using a legitimate Red Hat GPG key, contain an externally
introduced modification (Trojan Horse) that allows the package authors to have an
unknown impact. NOTE: since the malicious packages were not distributed from any
official Red Hat sources, the scope of this issue is restricted to users who may have
obtained these packages through unofficial distribution points. As of 20080827, no
unofficial distributions of this software are known.
2007
CVE-2007-2768
4.3OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM,
allows remote attackers to determine the existence of certain user accounts, which
displays a different response if the user account exists and is configured to use one-time
passwords (OTP), a similar issue to CVE-2007-2243.
Vulnerabilities
CVSS
Note: the device may not be impacted by all of these issues. The vulnerabilities are
implied based on the software and version.
Critical
CVE-2008-3844
9.3Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as
signed in August 2008 using a legitimate Red Hat GPG key, contain an externally
introduced modification (Trojan Horse) that allows the package authors to have an
unknown impact. NOTE: since the malicious packages were not distributed from any
official Red Hat sources, the scope of this issue is restricted to users who may have
obtained these packages through unofficial distribution points. As of 20080827, no
unofficial distributions of this software are known.
Medium
by HooangF4t
CVE-2020-15778
6.8scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote
function, as demonstrated by backtick characters in the destination argument. NOTE: the
vendor reportedly has stated that they intentionally omit validation of "anomalous
argument transfers" because that could "stand a great chance of breaking existing
workflows."
CVE-2019-6111
5.8An issue was discovered in OpenSSH 7.9. Due to the scp implementation being
derived from 1983 rcp, the server chooses which files/directories are sent to the client.
However, the scp client only performs cursory validation of the object name returned
(only directory traversal attacks are prevented). A malicious scp server (or Man-in-The-
Middle attacker) can overwrite arbitrary files in the scp client target directory. If
recursive operation (-r) is performed, the server can manipulate subdirectories as well (for
example, to overwrite the .ssh/authorized_keys file).
CVE-2017-15906
5.0The process_open function in sftp-server.c in OpenSSH before 7.6 does not
properly prevent write operations in readonly mode, which allows attackers to create
zero-length files.
CVE-2018-15473
5.0OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not
delaying bailout for an invalid authenticating user until after the packet containing the
request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-
pubkey.c.
CVE-2018-15919
5.0Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be
used by remote attackers to detect existence of users on a target system when GSS2 is in
use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not
want to treat such a username enumeration (or "oracle") as a vulnerability.'
CVE-2021-41617
4.4sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default
configurations are used, allows privilege escalation because supplemental groups are not
initialized as expected. Helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand may run with privileges associated with group
memberships of the sshd process, if the configuration specifies running the command as a
different user.
CVE-2007-2768
4.3OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM,
allows remote attackers to determine the existence of certain user accounts, which
by HooangF4t
displays a different response if the user account exists and is configured to use one-time
passwords (OTP), a similar issue to CVE-2007-2243.
CVE-2016-20012
4.3OpenSSH through 8.7 allows remote attackers, who have a suspicion that a
certain combination of username and public key is known to an SSH server, to test
whether this suspicion is correct. This occurs because a challenge is sent only when that
combination could be valid for a login session. NOTE: the vendor does not recognize
user enumeration as a vulnerability for this product
CVE-2020-14145
4.3The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy
leading to an information leak in the algorithm negotiation. This allows man-in-the-
middle attackers to target initial connection attempts (where no host key for the server
has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also
affected.
CVE-2019-6109
4.0An issue was discovered in OpenSSH 7.9. Due to missing character encoding in
the progress display, a malicious server (or Man-in-The-Middle attacker) can employ
crafted object names to manipulate the client output, e.g., by using ANSI control codes to
hide additional files being transferred. This affects refresh_progress_meter() in
progressmeter.c.
CVE-2019-6110
4.0In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the
server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client
output, for example to use ANSI control codes to hide additional files being transferred.
Low
CVE-2018-20685
2.6In OpenSSH 7.9, scp.c in the scp client allows remote SSH servers to bypass
intended access restrictions via the filename of . or an empty filename. The impact is
modifying the permissions of the target directory on the client side.
CVE-2021-36368
2.6An issue was discovered in OpenSSH before 8.9. If a client is using public-key
authentication with agent forwarding but without -oLogLevel=verbose, and an attacker
has silently modified the server to support the None authentication option, then the user
cannot determine whether FIDO authentication is going to confirm that the user wishes to
connect to that server, or that the user wishes to allow that server to connect to a different
server on the user's behalf. NOTE: the vendor's position is "this is not an authentication
bypass, since nothing is being bypassed.
by HooangF4t
Unscored
CVE-2023-38408
falseThe PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an
insufficiently trustworthy search path, leading to remote code execution if an agent is
forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for
loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-
2016-10009.
CVE-2023-48795
falseThe SSH transport protocol with certain OpenSSH extensions, found in
OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity
checks such that some packets are omitted (from the extension negotiation message), and
a client and server may consequently end up with a connection for which some security
features have been downgraded or disabled, aka a Terrapin attack. This occurs because
the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the
handshake phase and mishandles use of sequence numbers. For example, there is an
effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-
MAC). The bypass occurs in chacha20-poly1305@[Link] and (if CBC is used) the
-etm@[Link] MAC algorithms. This also affects Maverick Synergy Java SSH API
before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP,
PuTTY before 0.80, AsyncSSH before 2.14.2, [Link]/x/crypto before 0.17.0, libssh
before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera
Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6,
Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH
through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before
2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH
library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH
through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before
3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5
before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise
SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through [Link], the
net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for [Link], the
thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
CVE-2023-51385
falseIn ssh in OpenSSH before 9.6, OS command injection might occur if a user
name or host name has shell metacharacters, and this name is referenced by an expansion
token in certain situations. For example, an untrusted Git repository can have a
submodule with shell metacharacters in a user name or host name.
CVE-2023-51767
falseOpenSSH through 9.6, when common types of DRAM are used, might allow
row hammer attacks (for authentication bypass) because the integer value of
by HooangF4t
authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE:
this is applicable to a certain threat model of attacker-victim co-location in which the
attacker has user privileges.