Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-14821

27
FAUCET Score

OVERVIEW CVE-2025-14821 is a privilege escalation and man-in-the-middle vulnerability affecting libssh on Windows systems. The flaw stems from an insecure default configuration where the library automatically loads SSH configuration files from the C:\etc directory, a location that unprivileged local users can create and modify. This allows attackers to manipulate SSH connections and trusted host information. SEVERITY The vulnerability carries a CVSS score of 7.8 (HIGH) with a local attack vector requiring low complexity and low privilege access. No user interaction is required for exploitation. The impact is severe, affecting all three security pillars: confidentiality (ability to intercept communications), integrity (capacity to modify connections and host trust data), and availability of SSH communications. The attack enables security downgrades and man-in-the-middle attacks against SSH sessions. EXPLOITATION STATUS There is currently no evidence of active exploitation. The EPSS score of 0.00011 indicates minimal real-world exploitation likelihood relative to other CVEs, and the vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog. No public exploit code is currently known to be available. The vulnerability maintains an inactive status on threat intelligence hot lists, suggesting limited community or threat actor attention at present.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.12.0CPE matchmatch criteria
cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:redhat:hardened_images:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 14th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (2)

microsoft2026-Apr/CVE-2025-14821Important

Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

Apr 14, 2026
redhatCVE-2025-14821Low

libssh: libssh: Insecure default configuration leads to local man-in-the-middle attacks on Windows

Feb 10, 2026

References

access.redhat.com / errata/RHSA-2026:7067
Third Party Advisory
access.redhat.com / security/cve/CVE-2025-14821
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
libssh.org / 2026/02/10/libssh-0-12-0-and-0-11-4-security-releases
Release Notes