Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2023-48795 — advanced-cluster-security

🟡 CVSS 5.9 — Medium ⚠️ Exploit Public CWE-354 NVD
5.9
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Prefix Truncation Attack against ChaCha20-Poly1305 and Encrypt-then-MAC aka Terrapin

Summary

Terrapin is a prefix truncation attack targeting the SSH protocol. More precisely, Terrapin breaks the integrity of SSH's secure channel. By carefully adjusting the sequence numbers during the handshake, an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it.

Mitigations

To mitigate this protocol vulnerability, OpenSSH suggested a so-called "strict kex" which alters the SSH handshake to ensure a Man-in-the-Middle attacker cannot introduce unauthenticated messages as well as convey sequence number manipulation across handshakes.

Warning: To take effect, both the client and server must support this countermeasure.

As a stop-gap measure, peers may also (temporarily) disable the affected algorithms and use unaffected alternatives like AES-GCM instead until patches are available.

Details

The SSH specifications of ChaCha20-Poly1305 ([email protected]) and Encrypt-then-MAC (*[email protected] MACs) are vulnerable against an arbitrary prefix truncation attack (a.k.a. Terrapin attack). This allows for an extension negotiation downgrade by stripping the SSH_MSG_EXT_INFO sent after the first message after SSH_MSG_NEWKEYS, downgrading security, and disabling attack countermeasures in some versions of OpenSSH. When targeting Encrypt-then-MAC, this attack requires the use of a CBC cipher to be practically exploitable due to the internal workings of the cipher mode. Additionally, this novel attack technique can be used to exploit previously unexploitable implementation flaws in a Man-in-the-Middle scenario.

The attack works by an attacker injecting an arbitrary number of SSH_MSG_IGNORE messages during the initial key exchange and consequently removing the same number of messages just after the initial key exchange has concluded. This is possible due to missing authentication of the excess SSH_MSG_IGNORE messages and the fact that the implicit sequence numbers used within the SSH protocol are only checked after the initial key exchange.

In the case of ChaCha20-Poly1305, the attack is guaranteed to work on every connection as this cipher does not maintain an internal state other than the message's sequence number. In the case of Encrypt-Then-MAC, practical exploitation requires the use of a CBC cipher; while theoretical integrity is broken for all ciphers when using this mode, message processing will fail at the application layer for CTR and stream ciphers.

For more details see [https://terrapin-attack.com](https://terrapin-attack.com).

Impact

This attack targets the specification of ChaCha20-Poly1305 ([email protected]) and Encrypt-then-MAC (*[email protected]), which are widely adopted by well-known SSH implementations and can be considered de-facto standard. These algorithms can be practically exploited; however, in the case of Encrypt-Then-MAC, we additionally require the use of a CBC cipher. As a consequence, this attack works against all well-behaving SSH implementations supporting either of those algorithms and can be used to downgrade (but not fully strip) connection security in case SSH extension negotiation (RFC8308) is supported. The attack may also enable attackers to exploit certain implementation flaws in a man-in-the-middle (MitM) scenario.

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality none, integrity high, availability none.

CVSS metrics in full

The score comes from this vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: High — the attacker first has to win a race, learn a secret or otherwise prepare the target.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: None — nobody has to be tricked into anything.
  • Scope: Unchanged — the damage stays inside the vulnerable component.
  • Confidentiality impact: None.
  • Integrity impact: High — total loss, or loss the attacker controls.
  • Availability impact: None.

Weakness class

CVE-2023-48795 is classified as CWE-354: Improper Validation of Integrity Check Value. A checksum or integrity value is not verified properly, so tampered data passes as intact.

Affected software

CVE-2023-48795 is recorded against 72 packages.

  • advanced-cluster-security
  • asyncssh (fixed in 2.14.2)
  • ceph-storage
  • cert-manager-operator-for-red-hat-openshift
  • cluster-autoscaler-1.26 (fixed in 1.26.6-r1)
  • cluster-autoscaler-1.26-compat (fixed in 1.26.6-r1)
  • cluster-autoscaler-1.27 (fixed in 1.27.5-r1)
  • cluster-autoscaler-1.27-compat (fixed in 1.27.5-r1)
  • crushftp (fixed in 10.6.0)
  • crypto (fixed in 0.17.0)
  • cyclone-ssh (fixed in 2.3.4)
  • debian-linux
  • discovery
  • dropbear-ssh (fixed in 2022.83)
  • enterprise-linux
  • erlang\/otp (from 26.0 up to 26.2.1)
  • fedora
  • filezilla-client (fixed in 3.66.4)
  • freebsd (fixed in 12.4)
  • golang.org/x/crypto
  • jboss-enterprise-application-platform
  • jsch (fixed in 0.2.15)
  • keycloak
  • kitty (fixed in 0.76.1.13)
Show the remaining 48 packages
  • lanconfig
  • lcos (fixed in 3.66.4)
  • lcos-fx
  • lcos-lx
  • lcos-sx
  • libssh (fixed in 0.10.6)
  • libssh2 (fixed in 1.11.1)
  • macos (from 14.0 up to 14.4)
  • maverick-synergy-java-ssh-api (fixed in 3.1.0-snapshot)
  • net-ssh
  • nova (fixed in 11.8)
  • openshift-api-for-data-protection
  • openshift-container-platform
  • openshift-data-foundation
  • openshift-dev-spaces
  • openshift-developer-tools-and-services
  • openshift-gitops
  • openshift-pipelines
  • openshift-serverless
  • openshift-virtualization
  • openssh (fixed in 9.6)
  • openstack-platform
  • paramiko (from 2.5.0 up to 3.4.0)
  • pfsense-ce (fixed in 2.7.2)
  • pfsense-plus (fixed in 23.09.1)
  • pkixssh (fixed in 14.4)
  • proftpd (fixed in 1.3.8b)
  • putty (fixed in 0.80)
  • russh
  • securecrt (fixed in 9.4.3)
  • security
  • sftp-gateway-firmware (fixed in 3.4.6)
  • sftpgo (fixed in 2.5.6)
  • single-sign-on
  • ssh (from 5.0 up to 5.1.1)
  • ssh-client (fixed in 9.33)
  • ssh-server (fixed in 9.32)
  • ssh2
  • sshd (fixed in 2.11.0)
  • sshj (fixed in 0.37.0)
  • sshlib (fixed in 2.2.22)
  • storage
  • tera-term (fixed in 5.1)
  • thrussh (fixed in 0.35.1)
  • tinyssh (fixed in 20230101)
  • transmit-5 (fixed in 5.10.4)
  • winscp (fixed in 6.2.2)
  • xshell-7 (fixed in build__0144)

Timeline and source

Published on 18 December 2023 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from NVD.

References

packetstormsecurity.com
seclists.org
www.openwall.com
www.openwall.com
www.openwall.com
www.openwall.com
www.openwall.com
access.redhat.com
arstechnica.com
bugs.gentoo.org
bugzilla.redhat.com
bugzilla.suse.com
crates.io
filezilla-project.org
forum.netgate.com
git.libssh.org
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com
github.com

Other advisories for this package

advanced-cluster-security has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-354: Improper Validation of Integrity Check Value) in other software:

CVE-2023-48795 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity MEDIUM
CVSS Score 5.9
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CWE CWE-354
Public Exploit ⚠️ Yes
Source NVD
Published 2023-12-18
Updated 2026-08-20
Modified 2026-06-17

Affected Packages

Software From version Fixed in
advanced-cluster-security
asyncssh 2.14.2
ceph-storage
cert-manager-operator-for-red-hat-openshift
cluster-autoscaler-1.26 1.26.6-r1
cluster-autoscaler-1.26-compat 1.26.6-r1
cluster-autoscaler-1.27 1.27.5-r1
cluster-autoscaler-1.27-compat 1.27.5-r1
crushftp 10.6.0
crypto 0.17.0
cyclone-ssh 2.3.4
debian-linux
discovery
dropbear-ssh 2022.83
enterprise-linux
erlang\/otp 26.0 26.2.1
fedora
filezilla-client 3.66.4
freebsd 12.4
golang.org/x/crypto
jboss-enterprise-application-platform
jsch 0.2.15
keycloak
kitty 0.76.1.13
lanconfig
lcos 3.66.4
lcos-fx
lcos-lx
lcos-sx
libssh 0.10.6
libssh2 1.11.1
macos 14.0 14.4
maverick-synergy-java-ssh-api 3.1.0-snapshot
net-ssh
nova 11.8
openshift-api-for-data-protection
openshift-container-platform
openshift-data-foundation
openshift-dev-spaces
openshift-developer-tools-and-services
openshift-gitops
openshift-pipelines
openshift-serverless
openshift-virtualization
openssh 9.6
openstack-platform
paramiko 2.5.0 3.4.0
pfsense-ce 2.7.2
pfsense-plus 23.09.1
pkixssh 14.4
proftpd 1.3.8b
putty 0.80
russh
securecrt 9.4.3
security
sftp-gateway-firmware 3.4.6
sftpgo 2.5.6
single-sign-on
ssh 5.0 5.1.1
ssh-client 9.33
ssh-server 9.32
ssh2
sshd 2.11.0
sshj 0.37.0
sshlib 2.2.22
storage
tera-term 5.1
thrussh 0.35.1
tinyssh 20230101
transmit-5 5.10.4
winscp 6.2.2
xshell-7 build__0144

References

Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/21
Mailing List, Third Party Advisory http://seclists.org/fulldisclosure/2024/Mar/21

Similar Threats

Exploit Protection

Are you running advanced-cluster-security?

CVE-2023-48795 carries CVSS 5.9 Medium rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2023-48795 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2023