https://seclists.org/oss-sec/2025/q1/150: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Published Feb 21, 2025
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is classified as critical due to its potential to allow Man-in-the-Middle attacks.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, update OpenSSH to the latest version that addresses the vulnerability.
3
What systems are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects all versions of OpenSSH that utilize the VerifyHostKeyDNS feature.
4
Can CVE-2025-XXXX be exploited remotely?
Yes, CVE-2025-XXXX can be exploited remotely if an attacker can manipulate DNS responses.
5
What are the implications of CVE-2025-XXXX?
The implications of CVE-2025-XXXX include the risk of unauthorized access and potential data breaches due to compromised SSH connections.