MNBSD-2023-10 OpenSSH Prefix Truncation Attack in the SSH protocol

A man in the middle attacker can silently manipulate handshake messages to truncate extension negotiation messages potentially leading to less secure client authentication algorithms or deactivating keystroke timing attack countermeasures.

Aliases: CVE-2023-48795

Modified: 2023-12-27T00:00:00.000Z
Published: 2023-12-27T00:00:00.000Z

References

https://nvd.nist.gov/vuln/detail/CVE-2023-48795