asyncssh
PyPI3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting asyncsshpage 1 of 1
- CVE-2018-7749CRITICALCVSS 9.8EG 9.8✓ Fixed in 1.12.12018-03-12
vulnerable: 0.8.1 ... 1.9.0 (39 versions)
The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.
- CVE-2023-46445MEDIUMCVSS 5.9EG 5.9✓ Fixed in 2.14.12023-11-14
vulnerable: 0.8.1 ... 2.9.0 (78 versions)
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
- CVE-2023-46446MEDIUMCVSS 6.8EG 6.8✓ Fixed in 2.14.12023-11-14
vulnerable: 0.8.1 ... 2.9.0 (78 versions)
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
Check whether asyncssh is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for asyncssh CVEs against the assets you own.
Start Free Scan →