Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2008-5161

32
FAUCET Score

CVE-2008-5161 describes an information disclosure vulnerability in the SSH protocol affecting SSH Tectia products and OpenSSH 4.7p1. This flaw, occurring when block ciphers in CBC mode are used, allows remote attackers to potentially recover plaintext data from SSH sessions due to errors in handling. The vulnerability has a CVSS score of 2.6, indicating low severity. It requires high attack complexity (AC:H) and only impacts confidentiality (C:P), meaning data could be partially exposed but not altered or made unavailable. There is no evidence of active exploitation, and it is not listed in the KEV catalog. While a Metasploit module exists for SSH version scanning, there are no public exploits for this specific vulnerability, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
4.7p1CPE matchmatch criteria
cpe:2.3:a:openbsd:openssh:4.7p1:*:*:*:*:*:*:*
4.0CPE matchmatch criteria
cpe:2.3:a:ssh:tectia_client:4.0:*:*:*:*:*:*:*
4.0.1CPE matchmatch criteria
cpe:2.3:a:ssh:tectia_client:4.0.1:*:*:*:*:*:*:*
4.0.3CPE matchmatch criteria
cpe:2.3:a:ssh:tectia_client:4.0.3:*:*:*:*:*:*:*
4.0.4CPE matchmatch criteria
cpe:2.3:a:ssh:tectia_client:4.0.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.6LOW

AV:N/AC:H/Au:N/C:P/I:N/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
NONE
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
15.39%
Probability of exploitation in next 30 days
EPSS Percentile
96.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.1540 is in the 97th percentile among its peer group of 1,505 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: openssh-0:4.3p2-36.el5
View patch

Vendor Advisories (1)

redhatCVE-2008-5161Low

OpenSSH: Plaintext Recovery Attack against CBC ciphers

Nov 19, 2008

References

isc.sans.org / diary.html
kb.juniper.net / InfoCenter/index
lists.apple.com / archives/security-announce/2009/Nov/msg00000.html
marc.info
openssh.org / txt/cbc.adv
osvdb.org / 49872
osvdb.org / 50035
osvdb.org / 50036
rhn.redhat.com / errata/RHSA-2009-1287.html
secunia.com / advisories/32740
Vendor Advisory
secunia.com / advisories/32760
Vendor Advisory
secunia.com / advisories/32833
secunia.com / advisories/33121
secunia.com / advisories/33308
secunia.com / advisories/34857
secunia.com / advisories/36558
exchange.xforce.ibmcloud.com / vulnerabilities/46620
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
kc.mcafee.com / corporate/index
kc.mcafee.com / corporate/index
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11279
sunsolve.sun.com / search/document.do
support.apple.com / kb/HT3937
support.attachmate.com / techdocs/2398.html
support.avaya.com / elmodocs2/security/ASA-2008-503.htm
cpni.gov.uk / Docs/Vulnerability_Advisory_SSH.txt
kb.cert.org / vuls/id/958563
US Government Resource
rtpro.yamaha.co.jp / RT/FAQ/Security/CPNI957037.html
securityfocus.com / archive/1/498558/100/0/threaded
securityfocus.com / archive/1/498579/100/0/threaded
securityfocus.com / bid/32319
securitytracker.com / id
securitytracker.com / id
securitytracker.com / id
ssh.com / company/news/article/953
Vendor Advisory
vupen.com / english/advisories/2008/3172
vupen.com / english/advisories/2008/3173
vupen.com / english/advisories/2008/3409
vupen.com / english/advisories/2009/1135
vupen.com / english/advisories/2009/3184