CVE-2013-4548 describes a memory initialization vulnerability in OpenSSH versions 6.2 and 6.3, specifically within the mm_newkeys_from_blob function when using an AES-GCM cipher. This flaw allows authenticated attackers to bypass security restrictions like ForceCommand and login-shell by sending crafted packet data. With a CVSS score of 6.0, this vulnerability has a medium severity, requiring authenticated access and moderate attack complexity to achieve partial confidentiality, integrity, and availability impacts. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.2CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:6.2:*:*:*:*:*:*:* | ||
6.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:6.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.