https://seclists.org/oss-sec/2025/q1/193: MitM attack against OpenSSH's VerifyHostKeyDNS-enabled client
Published Mar 10, 2025
·Updated
Affected Software
1 affected component
OpenSSH OpenSSH
Frequently Asked Questions
1
What is the severity of CVE-2025-XXXX?
CVE-2025-XXXX is classified as a critical vulnerability due to its potential for facilitating Man-in-the-Middle (MitM) attacks.
2
How do I fix CVE-2025-XXXX?
To mitigate CVE-2025-XXXX, you should update your OpenSSH client to the latest version that addresses the vulnerability.
3
What systems are affected by CVE-2025-XXXX?
CVE-2025-XXXX specifically affects clients using VerifyHostKeyDNS in OpenSSH.
4
Is there a workaround for CVE-2025-XXXX if I cannot update?
A temporary workaround for CVE-2025-XXXX is to disable the VerifyHostKeyDNS option in your OpenSSH client configuration.
5
What type of attack does CVE-2025-XXXX enable?
CVE-2025-XXXX enables a Man-in-the-Middle (MitM) attack that can compromise the integrity of communications between the client and server.