OpenSSH: Plaintext Recovery Attack against CBC ciphers
Published Nov 19, 2008
3.7
LOWCVSS 3.1
EPSS 18.55%
Description
Error handling in the SSH protocol in (1) SSH Tectia Client and Server and Connector 4.0 through 4.4.11, 5.0 through 5.2.4, and 5.3 through 5.3.8; Client and Server and ConnectSecure 6.0 through 6.0.4; Server for Linux on IBM System z 6.0.4; Server for IBM z/OS 5.5.1 and earlier, 6.0.0, and 6.0.1; and Client 4.0-J through 4.3.3-J and 4.0-K through 4.3.10-K; and (2) OpenSSH 4.7p1 and possibly other versions, when using a block cipher algorithm in Cipher Block Chaining (CBC) mode, makes it easier for remote attackers to recover certain plaintext data from an arbitrary block of ciphertext in an SSH session via unknown vectors.
Affected products
No data.
- 4.7p1
- 4.0
- 4.0.1
- 4.0.3
- 4.0.4
- 4.0.5
- 4.2
- 4.2.1
- 4.3
- 4.3.1
- 4.3.1j
- 4.3.2
- 4.3.2j
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.3.8k
- 4.3.9k
- 4.4
- 4.4.1
- 4.4.2
- 4.4.3
- 4.4.4
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 4.4.10
- 4.4.11
- 5.0.0
- 5.0.0f
- 5.0.1
- 5.0.1f
- 5.0.2
- 5.0.2f
- 5.0.3
- 5.0.3f
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.2.0
- 5.2.1
- 5.2.2
- 5.2.3
- 5.2.4
- 5.3.0
- 5.3.1
- 5.3.2
- 5.3.3
- 5.3.5
- 5.3.6
- 5.3.7
- 5.3.8
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 4.0.7
- 4.1.2
- 4.1.3
- 4.1.5
- 4.2.0
- 4.3.0
- 4.3.4
- 4.3.5
- 4.4.0
- 4.4.2
- 4.4.4
- 4.4.6
- 4.4.7
- 4.4.9
- 4.4.10
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.1.0
- 5.1.1
- 5.1.2
- 5.1.3
- 5.2.2
- 5.3.0
- 5.3.1
- 5.3.2
- 5.3.3
- 5.3.7
- 5.3.8
- 6.0.0
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 4.0
- 4.0.3
- 4.0.4
- 4.0.5
- 4.0.7
- 4.1.2
- 4.1.3
- 4.1.5
- 4.2.0
- 4.2.1
- 4.2.2
- 4.3
- 4.3.0
- 4.3.1
- 4.3.2
- 4.3.3
- 4.3.4
- 4.3.5
- 4.3.6
- 4.3.7
- 4.4
- 4.4.0
- 4.4.1
- 4.4.2
- 4.4.4
- 4.4.5
- 4.4.6
- 4.4.7
- 4.4.8
- 4.4.9
- 4.4.10
- 4.4.11
- 5.0.0
- 5.0.1
- 5.0.2
- 5.0.3
- 5.1.0
- 5.1.1
- 5.1.1
- 5.1.2
- 5.1.3
- 5.2.0
- 5.2.0
- 5.2.1
- 5.2.2
- 5.2.2
- 5.2.3
- 5.2.4
- 5.3.0
- 5.3.0
- 5.3.1
- 5.3.2
- 5.3.3
- 5.3.4
- 5.3.5
- 5.3.6
- 5.3.7
- 5.3.8
- 5.4.0
- 5.4.1
- 5.4.2
- 5.5.0
- 5.5.1
- 6.0.0
- 6.0.0
- 6.0.1
- 6.0.1
- 6.0.2
- 6.0.3
- 6.0.4
- 6.0.4
No data.
Red Hat Enterprise Linux 5
openssh-0:4.3p2-36.el5
Fixed · RHSA-2009:1287
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | openssh-0:4.3p2-36.el5 | Fixed | RHSA-2009:1287 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue was addressed for Red Hat Enterprise Linux 5 by https://rhn.redhat.com/errata/RHSA-2009-1287.html After reviewing the upstream fix for this issue, Red Hat does not intend to address this flaw in Red Hat Enterprise Linux 4.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:H/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed May 28, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 18.55% (0.18551) | 97.17th | v5 (v2026.06.15) |
| Aug 24, 2026 | 18.55% (0.18551) | 97.02th | v5 (v2026.06.15) |
| Jun 15, 2026 | 15.39% (0.15395) | 96.36th | v5 (v2026.06.15) |
| May 29, 2026 | 1.60% (0.01602) | 82.01th | v4 (v2025.03.14) |
| Feb 15, 2026 | 2.75% (0.02747) | 85.67th | v4 (v2025.03.14) |
| Nov 4, 2025 | 4.35% (0.04355) | 88.41th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.07% (0.03067) | 85.82th | v4 (v2025.03.14) |
| Mar 16, 2025 | 56.80% (0.56800) | 97.92th | v3 (v2023.03.01) |
| Feb 8, 2025 | 60.16% (0.60157) | 97.96th | v3 (v2023.03.01) |
| Jan 1, 2025 | 49.80% (0.49800) | 97.62th | v3 (v2023.03.01) |
| Dec 17, 2024 | 64.57% (0.64572) | 98.04th | v3 (v2023.03.01) |
| Nov 25, 2024 | 52.54% (0.52545) | 97.69th | v3 (v2023.03.01) |
| Oct 20, 2024 | 61.15% (0.61151) | 97.87th | v3 (v2023.03.01) |
| Aug 12, 2024 | 59.61% (0.59613) | 97.82th | v3 (v2023.03.01) |
| Mar 18, 2024 | 12.27% (0.12268) | 95.25th | v3 (v2023.03.01) |
| Mar 7, 2024 | 11.22% (0.11216) | 95.03th | v3 (v2023.03.01) |
| Mar 7, 2023 | 1.05% (0.01049) | 81.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 4.36% (0.04358) | 88.02th | v2 (v2022.01.01) |
| Apr 1, 2022 | 4.36% (0.04358) | 86.83th | v2 (v2022.01.01) |
| Feb 4, 2022 | 4.36% (0.04358) | 70.59th | v2 (v2022.01.01) |
References (44)
- http://isc.sans.org/diary.html?storyid=5366 x_refsource_MISC
- http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10705 x_refsource_CONFIRM
- http://lists.apple.com/archives/security-announce/2009/Nov/msg00000.html vendor-advisoryx_refsource_APPLE
- http://marc.info/?l=bugtraq&m=125017764422557&w=2 vendor-advisoryx_refsource_HP
- http://openssh.org/txt/cbc.adv x_refsource_CONFIRM
- http://osvdb.org/49872 vdb-entryx_refsource_OSVDB
- http://osvdb.org/50035 vdb-entryx_refsource_OSVDB
- http://osvdb.org/50036 vdb-entryx_refsource_OSVDB
- http://rhn.redhat.com/errata/RHSA-2009-1287.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/32740 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/32760 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/32833 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33121 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/33308 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/34857 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/36558 third-party-advisoryx_refsource_SECUNIA
- http://sunsolve.sun.com/search/document.do?assetkey=1-66-247186-1 vendor-advisoryx_refsource_SUNALERT
- http://support.apple.com/kb/HT3937 x_refsource_CONFIRM
- http://support.attachmate.com/techdocs/2398.html x_refsource_CONFIRM
- http://support.avaya.com/elmodocs2/security/ASA-2008-503.htm x_refsource_MISC
- http://www.cpni.gov.uk/Docs/Vulnerability_Advisory_SSH.txt x_refsource_MISC
- http://www.kb.cert.org/vuls/id/958563 third-party-advisoryx_refsource_CERT-VNUS Government Resource
- http://www.rtpro.yamaha.co.jp/RT/FAQ/Security/CPNI957037.html x_refsource_CONFIRM
- http://www.securityfocus.com/archive/1/498558/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/498579/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/32319 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1021235 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id?1021236 vdb-entryx_refsource_SECTRACK
- http://www.securitytracker.com/id?1021382 vdb-entryx_refsource_SECTRACK
- http://www.ssh.com/company/news/article/953/ x_refsource_CONFIRMVendor Advisory
- http://www.vupen.com/english/advisories/2008/3172 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/3173 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/3409 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/1135 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2009/3184 vdb-entryx_refsource_VUPEN
- https://access.redhat.com/security/cve/CVE-2008-5161 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=472068 Issue Tracking
- https://exchange.xforce.ibmcloud.com/vulnerabilities/46620 vdb-entryx_refsource_XF
- https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05157667 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10106 x_refsource_CONFIRM
- https://kc.mcafee.com/corporate/index?page=content&id=SB10163 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2008-5161
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11279 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2008-5161
Change history (0)
No recorded changes yet.