216.73.216.233

CVE-2025-5372

· Published 04/07/2025 06:15 · Modified 04/07/2025 06:15

Labels: CVE-2025-5372 2025-07-04CVE-2025-5372CWE-682[email protected]

Essential information

Published
04/07/2025 06:15
Modified
04/07/2025 06:15
Author
Creator
CVSS
5.0 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

CVSS metrics

Description

A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even when key derivation fails. This results in uninitialized cryptographic key buffers being used in subsequent communication, potentially compromising SSH sessions' confidentiality, integrity, and availability.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
libssh / libssh cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:*
openssl / openssl cpe:2.3:a:openssl:openssl:<3.0:*:*:*:*:*:*:*

References