SSH is a cryptographic remote-access protocol and tooling vendor whose vulnerability footprint, though limited in product breadth, sits at a critical juncture in infrastructure security given SSH's ubiquity in server management, automation, and secure communications across nearly all enterprise and operational-technology environments. The vendor's durable exposure pattern centers on its core SSH implementation and commercial variants such as Tectia Server and Tectia Client, with recurring weaknesses clustered around authentication mechanisms, cryptographic initialization, and information disclosure—characteristic concerns for protocol-level software handling sensitive session material. Vulnerabilities affecting this vendor frequently attract public exploit development, reflecting the security-researcher interest in SSH tooling and the operational value of compromised credentials or session hijacking across target infrastructure. While most disclosures do not rise to critical severity, the strategic role of SSH in lateral movement and persistent access means even moderate-severity authentication or information-disclosure flaws warrant prompt inventory and patching. Defenders should treat SSH software updates as high-priority and maintain awareness of version distribution across managed systems, since this vendor's advisories often affect widely deployed legacy variants; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ssh over time
Signals from CVEs in this vendor scope (48 CVEs).
48 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2012-5975HIGH The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6.2.5, and 6.3.0 through 6.3.2 on UNIX and Linux, when old-st | Dec 4, 2012 | 9.3 | 67 | NO | YES |
CVE-2001-0144HIGH CORE SDI SSH1 CRC-32 compensation attack detector allows remote attackers to execute arbitrary commands on an SSH server or client via an integer overflow. | Mar 12, 2001 | 10.0 | 60 | NO | YES |
CVE-2002-1645HIGH Buffer overflow in the URL catcher feature for SSH Secure Shell for Workstations client 3.1 to 3.2.0 allows remote attackers to execute arbitrary code via a long URL. | Nov 25, 2002 | 10.0 | 33 | NO | NO |
CVE-2001-0553HIGH SSH Secure Shell 3.0.0 on Unix systems does not properly perform password authentication to the sshd2 daemon, which allows local users to gain access to accounts with short passwor | Aug 14, 2001 | 7.2 | 33 | NO | YES |
CVE-2001-1473HIGH The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Se | Jan 18, 2001 | 7.5 | 33 | NO | YES |
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecu | Nov 19, 2008 | 3.7 | 32 | NO | YES |
CVE-2001-0471HIGH SSH daemon version 1 (aka SSHD-1 or SSH-1) 1.2.30 and earlier does not log repeated login attempts, which could allow remote attackers to compromise accounts without detection via | Jun 27, 2001 | 7.5 | 30 | NO | YES |
CVE-2021-27891HIGH SSH Tectia Client and Server before 6.4.19 on Windows have weak key generation. ConnectSecure on Windows is affected. | Mar 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2002-1715HIGH SSH 1 through 3, and possibly other versions, allows local users to bypass restricted shells such as rbash or rksh by uploading a script to a world-writeable directory, then execut | Dec 31, 2002 | 7.2 | 27 | NO | YES |
Signals from CVEs in this vendor scope (48 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ssh.
Media articles that mention a CVE ID that affects a product developed by Ssh — matched by CVE ID, not by vendor name.