CVE-2025-26465
CVSS 3.1 Score 6.8 of 10 (medium)
Details
Published Feb 18, 2025
Updated: Mar 3, 2025
CWE ID 390
Summary
CVE-2025-26465 is a vulnerability affecting OpenSSH when the VerifyHostKeyDNS option is enabled. In this scenario, a man-in-the-middle attack is possible, with a malicious server impersonating a legitimate one. The attack arises due to OpenSSH's mishandling of error codes during host key verification under specific conditions. To execute a successful attack, an attacker must first exhaust the client's memory resources, making the attack complexity high.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share