https://seclists.org/oss-sec/2025/q1/144: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Published Feb 18, 2025
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH>=6.8p1, >=9.5p1
Frequently Asked Questions
1
What is the severity of CVE-2025-26465?
CVE-2025-26465 is considered a critical vulnerability due to its potential for facilitating Man-in-the-Middle attacks.
2
How do I fix CVE-2025-26465?
To fix CVE-2025-26465, update OpenSSH to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2025-26465?
CVE-2025-26465 affects clients that have the VerifyHostKeyDNS feature enabled in OpenSSH.
4
Can CVE-2025-26465 lead to data compromise?
Yes, CVE-2025-26465 can lead to data compromise by allowing attackers to intercept and manipulate connections.
5
What is a Man-in-the-Middle attack in the context of CVE-2025-26465?
In the context of CVE-2025-26465, a Man-in-the-Middle attack occurs when an attacker can intercept and alter communication between a client and an SSH server.