« List of all CVEs

CVE-2025-14821

Libssh: libssh: insecure default configuration leads to local man-in-the-middle attacks on windows

Published: 4/7/2026 Last updated: 6/30/2026 Reserved: 12/17/2025

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.1 7.8 High CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Opam packages affected (1)

libssh

Products affected (14)

Product Vendor Version
Red Hat Enterprise Linux 9 Red Hat 2012 (Core installation)
Red Hat Enterprise Linux 10 Red Hat All Jetson Linux versions prior to r32.6.1
Red Hat Enterprise Linux 10 Red Hat 7.0.1
Red Hat Enterprise Linux 8 Red Hat 2016
Red Hat Enterprise Linux 8 Red Hat Android-10
Red Hat Enterprise Linux 9 Red Hat n/a
Red Hat Enterprise Linux 6 Red Hat Android-12L
Red Hat Enterprise Linux 6 Red Hat < 6.1.28
Red Hat Enterprise Linux 7 Red Hat n/a
Red Hat Enterprise Linux 7 Red Hat 10 for x64-based Systems
Red Hat Hardened Images Red Hat < 0.27.5
Red Hat Hardened Images Red Hat < 20.3R2-EVO
Red Hat OpenShift Container Platform 4 Red Hat < 10.0.17763.2114
Red Hat OpenShift Container Platform 4 Red Hat unspecified

References (8)

Credits (2)