https://seclists.org/oss-sec/2025/q1/152: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Published Feb 21, 2025
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
The severity of CVE-2025-XXXX is considered high due to the potential for a MitM attack.
2
How do I fix CVE-2025-XXXX?
To fix CVE-2025-XXXX, you should upgrade to the latest version of OpenSSH that addresses this vulnerability.
3
Which versions of OpenSSH are affected by CVE-2025-XXXX?
CVE-2025-XXXX affects OpenSSH versions prior to the security update released on February 21, 2025.
4
What is the impact of CVE-2025-XXXX?
The impact of CVE-2025-XXXX includes the risk of Man-in-the-Middle attacks that can compromise session security.
5
Is there a workaround for CVE-2025-XXXX?
Currently, there are no effective workarounds for CVE-2025-XXXX other than upgrading to a patched OpenSSH version.