Vulnerabilities > CVE-2023-46446 - Authorization Bypass Through User-Controlled Key vulnerability in Asyncssh Project Asyncssh

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
high complexity
asyncssh-project
CWE-639

Summary

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

Vulnerable Configurations

Part Description Count
Application
Asyncssh_Project
50