CVE-2008-5161

LOW

SSH Version Scanner

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2008-5161. PoCs published by talha3117, including Metasploit module auxiliary/scanner/ssh/ssh_version.

AI-analyzed exploit summary This repository contains a Python script that automates version checking for OpenSSH 4.7p1 and uses Metasploit's ssh_login module to perform credential auditing. It does not exploit CVE-2008-5161 directly but serves as a helper tool for automated scanning.

Description

Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.

Exploits (2)

nomisec SCANNER
by talha3117 · poc
https://github.com/talha3117/OpenSSH-4.7p1-CVE-2008-5161-Exploit

This repository contains a Python script that automates version checking for OpenSSH 4.7p1 and uses Metasploit's ssh_login module to perform credential auditing. It does not exploit CVE-2008-5161 directly but serves as a helper tool for automated scanning.

Classification
Scanner 90%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: OpenSSH 4.7p1 Debian-8ubuntu1
No auth needed
Prerequisites: Metasploit Framework installed · pwntools installed · user:password wordlist
devstral-2 · analyzed Feb 18, 2026 Full analysis →
metasploit SCANNER
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ssh/ssh_version.rb

This Metasploit auxiliary module scans SSH servers to detect vulnerable encryption algorithms, including those affected by CVE-2008-5161 (CBC mode vulnerabilities). It checks for deprecated or weak ciphers, key exchange methods, and host keys.

Classification
Scanner 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: SSH servers (various implementations)
No auth needed
Prerequisites: Network access to target SSH port (default 22)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (40)

Core 40
Core References
Various Sources x_refsource_confirm
http://openssh.org/txt/cbc.adv
Vendor Advisory vendor-advisory x_refsource_sunalert
http://sunsolve.sun.com/search/document.do?assetkey=1-66-247186-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/32319
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33121
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/49872
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/33308
Vendor Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2009-1287.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021382
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50036
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32833
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/36558
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/50035
Vendor Advisory x_refsource_confirm
http://www.ssh.com/company/news/article/953/
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021235
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34857
Various Sources x_refsource_confirm
http://support.attachmate.com/techdocs/2398.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3173
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498579/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/46620
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32740
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1135
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32760
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3184
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1021236
Mailing List vendor-advisory x_refsource_hp
http://marc.info/?l=bugtraq&m=125017764422557&w=2
Various Sources x_refsource_misc
http://isc.sans.org/diary.html?storyid=5366
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3409
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/3172
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11279
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/498558/100/0/threaded
Vendor Advisory x_refsource_confirm
http://support.apple.com/kb/HT3937
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/958563

Scores

CVSS v3 3.7
EPSS 0.1540
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-329
Status published
Products (50)
openbsd/openssh 4.7p1
ssh/tectia_client 4.0
ssh/tectia_client 4.0.1
ssh/tectia_client 4.0.3
ssh/tectia_client 4.0.4
ssh/tectia_client 4.0.5
ssh/tectia_client 4.2
ssh/tectia_client 4.2.1
ssh/tectia_client 4.3
ssh/tectia_client 4.3.1
... and 40 more
Published Nov 19, 2008
Tracked Since Feb 18, 2026