Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-14821

Опубликовано: 07 апр. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.8

Описание

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

РелизСтатусПримечание
devel

not-affected

Only affects Windows
esm-infra-legacy/xenial

not-affected

Only affects Windows
esm-infra/bionic

not-affected

Only affects Windows
esm-infra/focal

not-affected

Only affects Windows
esm-infra/xenial

not-affected

Only affects Windows
jammy

not-affected

Only affects Windows
noble

not-affected

Only affects Windows
questing

not-affected

Only affects Windows
upstream

not-affected

debian: Only affects libssh on Windows

Показывать по

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
redhat
6 месяцев назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

CVSS3: 7.8
nvd
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

msrc
4 месяца назад

Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

CVSS3: 7.8
debian
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the ...

CVSS3: 7.8
github
4 месяца назад

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

EPSS

Процентиль: 3%
0.00129
Низкий

7.8 High

CVSS3