Back

HIGH

python-asyncssh: Rogue Session Attack

Published Nov 14, 2023

Description

An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."

Affected products

Remediation

No remediation recorded yet.

Metrics

References (14)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 14, 2023
Updated Feb 25, 2026
Reserved Oct 23, 2023
CISA Vulnrichment
Updated Dec 22, 2023
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Nov 13, 2023
GHSA-C35Q-FFPF-5QPM