Only server-side SSH deployments built with Apache MINA SSHD that include the optional sshd-ldap component and configure LdapPasswordAuthenticator for password authentication are affected. Built-in sshd-core password authentication is not affected.
The published CVSS vector indicates exploitation is network-accessible, requires no privileges or user interaction, and has low attack complexity. The flaw bypasses authentication checks in LdapPasswordAuthenticator.
Check whether the application uses Apache MINA SSHD versions 1.2.0 through 2.19.0 or 3.0.0-M1 through 3.0.0-M5, includes sshd-ldap, and configures LdapPasswordAuthenticator for SSH password authentication. If any of those LDAP-specific conditions are absent, the described issue does not apply.
Upgrade affected applications to Apache MINA SSHD 2.20.0 or 3.0.0-M6. The provided information does not specify an alternative mitigation for deployments that cannot immediately upgrade.