Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-14821

Опубликовано: 07 апр. 2026
Источник: nvd
CVSS3: 7.8
CVSS3: 7
EPSS Низкий

Описание

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
Версия до 0.12.0 (исключая)
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3

7 High

CVSS3

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

CVSS3: 7.8
redhat
6 месяцев назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

msrc
4 месяца назад

Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

CVSS3: 7.8
debian
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the ...

CVSS3: 7.8
github
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3

7 High

CVSS3

Дефекты

CWE-427