CVE-2023-46446, also known as a "Rogue Session Attack," affects AsyncSSH versions prior to 2.14.1, allowing attackers to manipulate SSH client sessions through packet injection/removal and shell emulation. This vulnerability carries a CVSS score of 6.8 (Medium), indicating a network-based attack with high complexity, requiring low privileges, and potentially leading to high confidentiality and integrity impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including an article on BleepingComputer concerning "Terrapin attacks" which are related to this class of vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.14.1CPE matchmatch criteria | cpe:2.3:a:asyncssh_project:asyncssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.