Junglewise Threat Intelligence

CVE-2023-46445: PYSEC-2023-237 - An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.

CVE-2023-46445 · Severity: low · CVSS 3.1 · Published 2023-11-14

Technologies: asyncssh (PyPI). Vendors: PyPI.

Executive brief

An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.

Affected products

  • PyPI asyncssh

Related threats