OpenSSH
cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*, +1 more
A vulnerability exists in OpenSSH versions prior to 10.3, where the handling of ECDSA algorithms in the PubkeyAcceptedAlgorithms and HostbasedAcceptedAlgorithms directives is flawed. If any ECDSA algorithm is listed, it is incorrectly interpreted to allow all ECDSA algorithms, leading to potential authentication issues.
This vulnerability could result in improper authentication by allowing unauthorized ECDSA algorithms to be accepted, potentially leading to unauthorized access or actions.
Users can upgrade to OpenSSH version 10.3 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.