CVE-2025-26466

medium

Description

The OpenSSH client and server are vulnerable to a pre-authentication denial-of-service attack: an asymmetric resource consumption of both memory and CPU. This vulnerability was introduced in August 2023 (shortly before OpenSSH 9.5p1).

References

https://www.securityweek.com/openssh-patches-vulnerabilities-allowing-mitm-dos-attacks/

https://www.bleepingcomputer.com/news/security/new-openssh-flaws-expose-ssh-servers-to-mitm-and-dos-attacks/

https://thehackernews.com/2025/02/new-openssh-flaws-enable-man-in-middle.html

Details

Source: Mitre, NVD

Published: 2025-02-20

Risk Information

CVSS v2

Base Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: Medium