icon

We found results for “

CVE-2025-26465

Date: February 18, 2025

In OpenSSH versions 6.8p1 to 9.9p1, a logic error in ssh(1) allowed an on-path attacker to impersonate any server when the VerifyHostKeyDNS option is enabled. This option is disabled by default.

Severity Score

Related Resources (26)

Severity Score

Weakness Type (CWE)

Channel Accessible by Non-Endpoint

CWE-300

Detection of Error Condition Without Action

CWE-390

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): HIGH
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): HIGH
Integrity (I): HIGH
Availability (A): NONE

Do you need more information?

Contact Us