Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Asyncssh
(Asyncssh_project)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 4 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2023-11-14 | CVE-2023-46445 | An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation." | Asyncssh | 5.9 | ||
2023-11-14 | CVE-2023-46446 | An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack." | Asyncssh | 6.8 | ||
2018-03-12 | CVE-2018-7749 | The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step. | Asyncssh | 9.8 |