Description
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3899-1 | python-asyncssh security update |
Github GHSA |
GHSA-cfc2-wr2v-gxm5 | AsyncSSH Rogue Extension Negotiation |
Ubuntu USN |
USN-7108-1 | AsyncSSH vulnerabilities |
Ubuntu USN |
USN-7108-2 | AsyncSSH vulnerabilities |
References
History
Mon, 03 Nov 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-25T17:20:12.613Z
Reserved: 2023-10-23T00:00:00.000Z
Link: CVE-2023-46445
No data.
Status : Modified
Published: 2023-11-14T03:15:09.470
Modified: 2026-02-25T18:18:07.057
Link: CVE-2023-46445
OpenCVE Enrichment
No data.
Debian DLA
Github GHSA
Ubuntu USN