Executive brief
An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.
Affected products
- PyPI asyncssh
Junglewise Threat Intelligence
CVE-2023-46445 · Severity: low · CVSS 3.1 · Published 2023-11-14
Technologies: asyncssh (PyPI). Vendors: PyPI.
An issue in AsyncSSH v2.14.0 and earlier allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack.