CVE-2021-36369 is a high-severity vulnerability in Dropbear SSH versions through 2020.81, affecting Debian Linux and Dropbear SSH Project products. It stems from a non-RFC-compliant check of authentication methods in the client-side SSH code, allowing a malicious SSH server to manipulate the login process. This flaw can bypass security measures like FIDO2 tokens or SSH-Askpass, enabling an attacker to abuse a forwarded agent for unauthorized access to other servers. While rated 7.5 HIGH on CVSS, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2020.81CPE matchmatch criteria | cpe:2.3:a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.