S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Network Vulnerabilities·Updated Sep 22, 2026

CVE-2023-48795 Scanner

CVE-2023-48795 Scanner - Bypass Integrity Checks vulnerability in OpenSSH

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsdomain, subdomain, ipv4
CostFree
3
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

OpenSSH is a widely-used software suite that implements secure shell (SSH) protocols, providing encrypted communication sessions over a computer network. It is commonly used by system administrators and developers to manage systems and applications remotely, securely transferring files, running commands, and providing secure access to systems. The suite supports various cryptographic algorithms and authentication methods, making it a favored choice for secure communications.

The vulnerability found in OpenSSH before version 9.6 allows remote attackers to bypass protocol-level integrity checks. This results in some security features being downgraded or disabled during SSH connections. The issue originates from flaws in the handling of extensions and sequence numbers in the SSH transport protocol. Consequently, these lapses can lead to compromised security when using certain cryptographic algorithms, specifically ChaCha20-Poly1305 and CBC with Encrypt-then-MAC.

Technical details involve an attack mechanism referred to as Terrapin, targeting specific OpenSSH extensions and their handling of the SSH Binary Packet Protocol. During the handshake phase, incorrect processing of sequence numbers allows attackers to intercept and manipulate the negotiation message. The vulnerabilities can heavily impact SSH connections using the [email protected] and [email protected] MAC algorithms, potentially leading to weakened cryptographic assurances.

Exploitation of this vulnerability may lead to critical security features being downgraded, thereby putting sensitive data at risk during SSH sessions. Malicious actors could gain the ability to effectively orchestrate man-in-the-middle attacks, eavesdrop on supposedly secure communications, or tamper with data integrity. The vulnerability poses a threat to any operation depending on the secure transmission of information.

REFERENCES

Solution Advice
  • Update the OpenSSH implementation to a version newer than 9.6 to ensure the vulnerability is patched.
  • Configure the SSH server to disable [email protected] encryption and [email protected] MAC algorithms.
  • Regularly apply security patches and updates to your SSH clients and servers.
  • Implement monitoring tools to detect unusual SSH activity that might indicate an exploitation attempt.
  • Consider alternative security algorithms not affected by the vulnerability, such as AES-GCM.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.