• caglararli@hotmail.com
  • 05386281520

CVE-2024-39894 | OpenSSH 9.5/9.6/9.7 echo-off Password Entry ObscureKeystrokeTiming timing discrepancy

Çağlar Arlı      -    33 Views

CVE-2024-39894 | OpenSSH 9.5/9.6/9.7 echo-off Password Entry ObscureKeystrokeTiming timing discrepancy

A vulnerability classified as problematic was found in OpenSSH 9.5/9.6/9.7. Affected by this vulnerability is the function ObscureKeystrokeTiming of the component echo-off Password Entry Handler. The manipulation leads to observable timing discrepancy. This vulnerability is known as CVE-2024-39894. The attack needs to be initiated within the local network. There is no exploit available. It is recommended to upgrade the affected component.