CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products,...
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). The bypass occurs in chacha20-poly1305@openssh.com and (if CBC is used) the -etm@openssh.com MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.
Security readout for executives and security teams
Plain-English summary
CVE-2023-48795, known as Terrapin, lets a network-positioned attacker interfere with SSH connection setup and silently remove some negotiation messages. The result can be a downgraded SSH session with certain protections disabled. It is broad across SSH clients, servers, and libraries, but the cited data does not show active exploitation.
Executive priority
Handle this as a broad dependency remediation issue, not a single server patch. Prioritize exposed SSH/SFTP services and widely deployed clients, then work through embedded libraries and appliances during normal vulnerability management cycles.
Technical view
The flaw is in SSH transport handling with certain OpenSSH extensions. Sequence number and handshake handling can allow omitted extension negotiation packets, affecting chacha20-poly1305@openssh.com and CBC Encrypt-then-MAC modes. OpenSSH before 9.6 and many SSH implementations or libraries are listed as affected.
Likely exposure
Exposure is likely wherever affected SSH, SFTP, or embedded SSH libraries are used in servers, clients, automation, appliances, developer tools, or file-transfer products. The bundle lists many affected implementations, so indirect exposure through dependencies is important.
Exploitation context
The CVSS vector is network-reachable, unauthenticated, no user interaction, but high attack complexity. The provided sources do not indicate CISA KEV listing or confirmed active exploitation, so treat exploitation as plausible but not source-confirmed.
Researcher notes
Evidence supports a protocol negotiation integrity bypass with broad implementation impact. The bundle provides affected version ranges and several vendor references, but not a complete asset-specific fix matrix or proof of active exploitation.
Mitigation direction
Upgrade OpenSSH to 9.6 or later where applicable.
Update affected SSH clients, servers, and libraries to vendor-fixed versions.
Prioritize internet-facing SSH and SFTP services first.
Review vendor guidance before changing algorithms or compatibility settings.
Update bundled dependencies in applications and appliances.
Validation and detection
Inventory SSH implementations and library versions across servers and endpoints.
Check SFTP gateways, appliances, and developer tools for affected SSH components.
Confirm OpenSSH, PuTTY, Dropbear, Paramiko, Go crypto, and AsyncSSH versions where used.
Verify vendor advisories or release notes show Terrapin fixes applied.
Document remaining legacy systems requiring compensating controls.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-354: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-354 · source CWE mapping
Improper Validation of Integrity Check Value
Improper Validation of Integrity Check Value represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.