Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-14821

Опубликовано: 10 фев. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

Отчет

This vulnerability is rated Low for Red Hat products. The flaw in libssh is specific to its insecure default configuration on Windows systems, where it loads configuration from the C:\etc directory. Red Hat's Linux-based products do not utilize this configuration path, and therefore are not affected by this vulnerability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsshNot affected
Red Hat Enterprise Linux 6libssh2Not affected
Red Hat Enterprise Linux 7libssh2Not affected
Red Hat Enterprise Linux 8libsshNot affected
Red Hat Enterprise Linux 9libsshNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imageslibssh-main-0.12.0-1.1.hum1FixedRHSA-2026:706708.04.2026

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-427
https://bugzilla.redhat.com/show_bug.cgi?id=2423148libssh: libssh: Insecure default configuration leads to local man-in-the-middle attacks on Windows

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

CVSS3: 7.8
nvd
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

msrc
4 месяца назад

Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

CVSS3: 7.8
debian
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the ...

CVSS3: 7.8
github
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3