Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.114398
Category:General
Title:OpenBSD OpenSSH <= 9.6 Authentication Bypass Vulnerability
Summary:OpenBSD OpenSSH is prone to an authentication bypass; vulnerability.;; Note: This VT has been deprecated and is therefore no longer functional. Please see the solution; tag for more information.
Description:Summary:
OpenBSD OpenSSH is prone to an authentication bypass
vulnerability.

Note: This VT has been deprecated and is therefore no longer functional. Please see the solution
tag for more information.

Vulnerability Insight:
When common types of DRAM are used, OpenSSH might allow row
hammer attacks (for authentication bypass) because the integer value of authenticated in
mm_answer_authpassword does not resist flips of a single bit.

NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the
attacker has user privileges.

Affected Software/OS:
OpenBSD OpenSSH version 9.6 and prior.

Solution:
No solution is required.

Vendor statement: This attack was not demonstrated against stock OpenSSH, but instead against a
modified sshd that had extra synchronisation added to make the attack easier.

Nobody has demonstrated this attack against a configuration remotely approximating real-world
conditions. We consider rowhammer mitigation to the job of the platform, not userspace
software.

CVSS Score:
6.0

CVSS Vector:
AV:L/AC:H/Au:S/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2023-51767
https://access.redhat.com/security/cve/CVE-2023-51767
https://arxiv.org/abs/2309.02545
https://bugzilla.redhat.com/show_bug.cgi?id=2255850
https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77
https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878
https://ubuntu.com/security/CVE-2023-51767
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.