CVE-2019-3863 is a critical vulnerability in libssh2 versions prior to 1.8.1, impacting products like Debian, NetApp, OpenSUSE, and Red Hat. This flaw allows a malicious SSH server to trigger an out-of-bounds memory write on a connecting client by sending oversized keyboard interactive responses. With a CVSS score of 8.8 (HIGH), it presents a significant risk, enabling remote attackers to achieve high confidentiality, integrity, and availability impacts with low attack complexity, though user interaction is required. Despite its severity and media coverage, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, and community discussion remains limited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.8.1CPE matchmatch criteria | cpe:2.3:a:libssh2:libssh2:*:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* | ||
15.0CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
42.3CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:42.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.