CVE-2024-39223

CRITICAL

gost 2.11.5 - Authentication Bypass via SSH HostKeyCallback Misconfiguration

Title source: llm
STIX 2.1

Description

An authentication bypass in the SSH service of gost v2.11.5 allows attackers to intercept communications via setting the HostKeyCallback function to ssh.InsecureIgnoreHostKey

Scores

CVSS v3 9.8
EPSS 0.0070
EPSS Percentile 48.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-639
Status published
Products (1)
ginuerzh/gost 0Go
Published Jul 03, 2024
Tracked Since Feb 18, 2026