Junglewise Threat Intelligence

CVE-2023-48795: OpenSSH and others SSH prefix truncation vulnerability (Terrapin)

CVE-2023-48795 · Severity: medium · CVSS 5.9 · Published 2023-12-18

Technologies: Paramiko, Putty, paramiko (PyPI), Golang.Org/X/ Crypto, Libssh2, golang.org/x/crypto (Go), Libssh, Openssh. Vendors: Paramiko, Putty, PyPI, Libssh2, Go, Libssh.

Executive brief

A vulnerability in the SSH protocol, known as Terrapin, allows an attacker positioned between a client and a server to silently drop security-related messages during the initial connection setup. This can be used to downgrade the connection's security features or disable certain defenses without either party noticing. While it does not allow for full decryption of the session, it weakens the overall protection of the encrypted tunnel used for remote access and data transfer.

Technical details

The Terrapin attack exploits a flaw in the SSH transport layer protocol when using specific encryption modes like ChaCha20-Poly1305 or Encrypt-then-MAC (EtM) with CBC. By injecting 'SSH_MSG_IGNORE' messages during the initial unauthenticated handshake and subsequently removing an equal number of encrypted packets after the key exchange, a Man-in-the-Middle (MitM) attacker can truncate the beginning of the secure channel. This is possible because sequence numbers are not authenticated until after the handshake is complete. The attack can be used to strip 'SSH_MSG_EXT_INFO' messages, effectively downgrading extension negotiation and disabling security features like keystroke obfuscation. Mitigation requires both client and server to implement the 'strict key exchange' (strict kex) extension.

Affected products

  • golang.org/x/ crypto >= 0.1.0, < 0.17.0
  • pip paramiko >= 2.5.0, < 3.4.0
  • cargo russh < 0.40.2
  • OpenSSH OpenSSH < 9.6

Timeline

  • 2023-12-18: disclosed: Public disclosure of the Terrapin attack.
  • 2023-12-18: advisory

References

Related threats