Vulnerabilities
Vulnerable Software
Openbsd:  >> Openssh  >> 10.3  Security Vulnerabilities
In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.
CVSS Score
5.9
EPSS Score
0.002
Published
2026-07-08
sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.
CVSS Score
3.7
EPSS Score
0.004
Published
2026-07-08
sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-07-08
ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)
CVSS Score
7.7
EPSS Score
0.003
Published
2026-07-08
sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.
CVSS Score
4.2
EPSS Score
0.003
Published
2026-07-08
scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.
CVSS Score
4.2
EPSS Score
0.003
Published
2026-07-08
internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.
CVSS Score
4.2
EPSS Score
0.002
Published
2026-07-08
sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.
CVSS Score
4.8
EPSS Score
0.002
Published
2026-07-08
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
CVSS Score
7.0
EPSS Score
0.007
Published
2023-12-24
Certain Red Hat Enterprise Linux (RHEL) 4 and 5 packages for OpenSSH, as signed in August 2008 using a legitimate Red Hat GPG key, contain an externally introduced modification (Trojan Horse) that allows the package authors to have an unknown impact. NOTE: since the malicious packages were not distributed from any official Red Hat sources, the scope of this issue is restricted to users who may have obtained these packages through unofficial distribution points. As of 20080827, no unofficial distributions of this software are known.
CVSS Score
9.3
EPSS Score
0.027
Published
2008-08-27


Contact Us

Shodan ® - All rights reserved