CVE-2023-48795: OpenSSH Terrapin attack (CVE-2023-48795)
Summary
Terrapin is a prefix truncation attack targeting the SSH protocol. More precisely, Terrapin breaks the integrity of SSH's secure channel. By carefully adjusting the sequence numbers during the handshake, an attacker can remove an arbitrary amount of messages sent by the client or server at the beginning of the secure channel without the client or server noticing it.
Mitigations
To mitigate this protocol vulnerability, OpenSSH suggested a so-called "strict kex" which alters the SSH handshake to ensure a Man-in-the-Middle attacker cannot introduce unauthenticated messages as well as convey sequence number manipulation across handshakes.
Warning: To take effect, both the client and server must support this countermeasure.
As a stop-gap measure, peers may also (temporarily) disable the affected algorithms and use unaffected alternatives like AES-GCM instead until patches are available.
Details
The SSH specifications of ChaCha20-Poly1305 (chacha20-poly1305@openssh.com) and Encrypt-then-MAC (-etm@openssh.com MACs) are vulnerable against an arbitrary prefix truncation attack (a.k.a. Terrapin attack). This allows for an extension negotiation downgrade by stripping the SSHMSGEXTINFO sent after the first message after SSHMSGNEWKEYS, downgrading security, and disabling attack countermeasures in some versions of OpenSSH. When targeting Encrypt-then-MAC, this attack requires the use of a CBC cipher to be practically exploitable due to the internal workings of the cipher mode. Additionally, this novel attack technique can be used to exploit previously unexploitable implementation flaws in a Man-in-the-Middle scenario.
The attack works by an attacker injecting an arbitrary number of SSHMSGIGNORE messages during the initial key exchange and consequently removing the same number of messages just after the initial key exchange has concluded. This is possible due to missing authentication of the excess SSHMSGIGNORE messages and the fact that the implicit sequence numbers used within the SSH protocol are only checked after the initial key exchange.
In the case of ChaCha20-Poly1305, the attack is guaranteed to work on every connection as this cipher does not maintain an internal state other than the message's sequence number. In the case of Encrypt-Then-MAC, practical exploitation requires the use of a CBC cipher; while theoretical integrity is broken for all ciphers when using this mode, message processing will fail at the application layer for CTR and stream ciphers.
For more details see https://terrapin-attack.com.
Impact
This attack targets the specification of ChaCha20-Poly1305 (chacha20-poly1305@openssh.com) and Encrypt-then-MAC (-etm@openssh.com), which are widely adopted by well-known SSH implementations and can be considered de-facto standard. These algorithms can be practically exploited; however, in the case of Encrypt-Then-MAC, we additionally require the use of a CBC cipher. As a consequence, this attack works against all well-behaving SSH implementations supporting either of those algorithms and can be used to downgrade (but not fully strip) connection security in case SSH extension negotiation (RFC8308) is supported. The attack may also enable attackers to exploit certain implementation flaws in a man-in-the-middle (MitM) scenario.
Other sources
Accessibility. A privacy issue was addressed with improved private data redaction for log entries.
— Apple
Admin Framework. A logic issue was addressed with improved checks.
— Apple
Airport. This issue was addressed with improved redaction of sensitive information.
— Apple
AppKit. A logic issue was addressed with improved restrictions.
— Apple
AppleMobileFileIntegrity. A downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions.
— Apple
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apple macOSto a version that resolves this vulnerability.Fixed in 14.4 - Upgrade
Upgrade
go/golang.org/x/cryptoto a version that resolves this vulnerability.Fixed in 0.0.0-20231218163308-9d2ee975ef9f - Upgrade
Upgrade
go/golang.org/x/cryptoto a version that resolves this vulnerability.Fixed in 0.17.0 - Upgrade
Upgrade
pip/paramikoto a version that resolves this vulnerability.Fixed in 3.4.0 - Upgrade
Upgrade
rust/russhto a version that resolves this vulnerability.Fixed in 0.40.2 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.2.14Fixed in 11.1.8Fixed in 11.2.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 5.6.19Fixed in 6.1.8Fixed in 6.3.2 - Upgrade
Upgrade
redhat/PuTTYto a version that resolves this vulnerability.Fixed in 0.80 - Upgrade
Upgrade
redhat/AsyncSSHto a version that resolves this vulnerability.Fixed in 2.14.1 - Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.9.8 - Upgrade
Upgrade
redhat/libsshto a version that resolves this vulnerability.Fixed in 0.10.6 - Upgrade
Upgrade
redhat/golang.org/x/crypto/sshto a version that resolves this vulnerability.Fixed in 0.17.0 - Upgrade
Upgrade
debian/dropbearto a version that resolves this vulnerability.Fixed in 2020.81-3+deb11u2Fixed in 2020.81-3+deb11u3Fixed in 2022.83-1+deb12u3Fixed in 2025.89-1~deb13u1Fixed in 2026.93-1Fixed in 2026.94-1 - Upgrade
Upgrade
debian/erlangto a version that resolves this vulnerability.Fixed in 1:23.2.6+dfsg-1+deb11u4Fixed in 1:25.2.3+dfsg-1+deb12u4Fixed in 1:25.2.3+dfsg-1+deb12u1Fixed in 1:27.3.4.1+dfsg-1+deb13u2Fixed in 1:29.0.3+dfsg-1 - Upgrade
Upgrade
debian/filezillato a version that resolves this vulnerability.Fixed in 3.52.2-3+deb11u1Fixed in 3.63.0-1+deb12u3Fixed in 3.68.1-1Fixed in 3.70.6-2 - Upgrade
Upgrade
debian/golang-go.cryptoto a version that resolves this vulnerability.Fixed in 1:0.25.0-1Fixed in 1:0.53.0-1 - Upgrade
Upgrade
debian/jschto a version that resolves this vulnerability.Fixed in 0.1.55-1Fixed in 0.2.19-1 - Upgrade
Upgrade
debian/libsshto a version that resolves this vulnerability.Fixed in 0.9.8-0+deb11u1Fixed in 0.9.8-0+deb11u2Fixed in 0.10.6-0+deb12u2Fixed in 0.10.6-0+deb12u1Fixed in 0.11.2-1+deb13u1Fixed in 0.12.0-3 - Upgrade
Upgrade
debian/libssh2to a version that resolves this vulnerability.Fixed in 1.9.0-2+deb11u1Fixed in 1.10.0-3Fixed in 1.11.1-1+deb13u1Fixed in 1.11.1-4 - Upgrade
Upgrade
debian/opensshto a version that resolves this vulnerability.Fixed in 1:8.4p1-5+deb11u3Fixed in 1:8.4p1-5+deb11u7Fixed in 1:9.2p1-2+deb12u10Fixed in 1:9.2p1-2+deb12u9Fixed in 1:10.0p1-7+deb13u4Fixed in 1:10.0p1-7+deb13u2Fixed in 1:10.3p1-5Fixed in 1:10.4p1-2 - Upgrade
Upgrade
debian/paramikoto a version that resolves this vulnerability.Fixed in 3.5.1-3Fixed in 4.0.0-4 - Upgrade
Upgrade
debian/php-phpseclibto a version that resolves this vulnerability.Fixed in 2.0.30-2+deb11u2Fixed in 2.0.30-2+deb11u3Fixed in 2.0.42-1+deb12u5Fixed in 2.0.42-1+deb12u3Fixed in 2.0.48-3+deb13u3Fixed in 2.0.48-3+deb13u1Fixed in 2.0.55-1 - Upgrade
Upgrade
debian/php-phpseclib3to a version that resolves this vulnerability.Fixed in 3.0.19-1+deb12u6Fixed in 3.0.19-1+deb12u4Fixed in 3.0.43-2+deb13u3Fixed in 3.0.43-2+deb13u1Fixed in 3.0.55-1 - Upgrade
Upgrade
debian/phpseclibto a version that resolves this vulnerability.Fixed in 1.0.19-3+deb11u2Fixed in 1.0.19-3+deb11u3Fixed in 1.0.20-1+deb12u5Fixed in 1.0.20-1+deb12u3Fixed in 1.0.23-6+deb13u3Fixed in 1.0.23-6+deb13u1Fixed in 1.0.30-1 - Upgrade
Upgrade
debian/proftpd-dfsgto a version that resolves this vulnerability.Fixed in 1.3.7a+dfsg-12+deb11u5Fixed in 1.3.8+dfsg-4+deb12u5Fixed in 1.3.8+dfsg-4+deb12u4Fixed in 1.3.8.c+dfsg-4+deb13u2Fixed in 1.3.9c~dfsg-1 - Upgrade
Upgrade
debian/proftpd-mod-proxyto a version that resolves this vulnerability.Fixed in 0.9.2-1+deb12u1Fixed in 0.9.5-1Fixed in 0.9.7-1 - Upgrade
Upgrade
debian/puttyto a version that resolves this vulnerability.Fixed in 0.74-1+deb11u2Fixed in 0.74-1+deb11u1Fixed in 0.78-2+deb12u2Fixed in 0.78-2+deb12u1Fixed in 0.83-3Fixed in 0.84-1 - Upgrade
Upgrade
debian/python-asyncsshto a version that resolves this vulnerability.Fixed in 2.5.0-0.1+deb11u1Fixed in 2.10.1-2+deb12u2Fixed in 2.10.1-2+deb12u1Fixed in 2.20.0-1Fixed in 2.23.0-1 - Upgrade
Upgrade
debian/tinysshto a version that resolves this vulnerability.Fixed in 20250501-1Fixed in 20260601-1 - Upgrade
Upgrade
PAN-OS SSH clientto a version that resolves this vulnerability.Fixed in 10.2.11 - Upgrade
Upgrade
PAN-OS SSH clientto a version that resolves this vulnerability.Fixed in 11.0.6 - Upgrade
Upgrade
PAN-OS SSH clientto a version that resolves this vulnerability.Fixed in 11.1.3 - Upgrade
Upgrade
PAN-OS SSH serverto a version that resolves this vulnerability.Fixed in 10.2.14 - Upgrade
Upgrade
PAN-OS SSH serverto a version that resolves this vulnerability.Fixed in 11.1.8 - Upgrade
Upgrade
PAN-OS SSH serverto a version that resolves this vulnerability.Fixed in 11.2.8 - Upgrade
Upgrade
Prisma SD-WAN IONto a version that resolves this vulnerability.Fixed in 5.6.19 - Upgrade
Upgrade
Prisma SD-WAN IONto a version that resolves this vulnerability.Fixed in 6.1.8 - Upgrade
Upgrade
Prisma SD-WAN IONto a version that resolves this vulnerability.Fixed in 6.3.2 - Configuration
As a stop-gap workaround until patches are available, configure the in-use SSH profile so it contains at least one cipher and at least one MAC algorithm; this removes support for CHACHA20-POLY1305 and all Encrypt-then-MAC algorithms in PAN-OS software.
PAN-OS SSH profile (management interface) in-use SSH profile ciphers/MACs = Configure at least one cipher and at least one MAC algorithm (removes CHACHA20-POLY1305 and all *-etm@openssh.com Encrypt-then-MAC algorithms). - Compensating control
If using the PAN-OS SSH client to connect to an external SSH server, ensure that the external SSH server does not support the CHACHA20-POLY1305 algorithm or any Encrypt-then-MAC algorithms.
- Compensating control
Use a PAN-OS configuration that removes support for the impacted algorithms: configure the system to exclusively use strong cipher algorithms or operate in FIPS-CC mode (this removes support for the impacted algorithms and prevents exploitation of this issue).
Event History
Parent advisories
This vulnerability appears in the following advisories.
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-23291
- CVE-2024-23276
- CVE-2024-23227
- CVE-2024-27886
- CVE-2024-23233
- CVE-2024-23269
- CVE-2024-23288
- CVE-2024-23277
- CVE-2024-23247
- CVE-2024-23248
- CVE-2024-23249
- CVE-2024-23250
- CVE-2024-23299
- CVE-2024-23244
- CVE-2024-23205
- CVE-2022-48554
- CVE-2024-23229
- CVE-2024-27789
- CVE-2024-23253
- CVE-2024-23270
- CVE-2024-23257
- CVE-2024-23258
- CVE-2024-23286
- CVE-2024-23234
- CVE-2024-23266
- CVE-2024-23235
- CVE-2024-23265
- CVE-2024-23225
- CVE-2024-27853
- CVE-2024-23278
- CVE-2024-0258
- CVE-2024-23279
- CVE-2024-23287
- CVE-2024-23264
- CVE-2024-23285
- CVE-2024-27809
- CVE-2024-23283
- CVE-2024-27887
- CVE-2023-48795
- CVE-2023-51384
- CVE-2023-51385
- CVE-2022-42816
- CVE-2024-23216
- CVE-2024-23267
- CVE-2024-23268
- CVE-2024-23274
- CVE-2023-42853
- CVE-2024-23275
- CVE-2024-27888
- CVE-2024-23255
- CVE-2024-23294
- CVE-2024-23296
- CVE-2024-23259
- CVE-2024-23273
- CVE-2024-23238
- CVE-2024-23239
- CVE-2024-23290
- CVE-2024-23232
- CVE-2024-23231
- CVE-2024-23230
- CVE-2024-23245
- CVE-2024-23292
- CVE-2024-23289
- CVE-2024-23293
- CVE-2024-23241
- CVE-2024-23272
- CVE-2024-23242
- CVE-2024-23281
- CVE-2024-27792
- CVE-2024-23261
- CVE-2024-23260
- CVE-2024-23246
- CVE-2024-23226
- CVE-2024-23254
- CVE-2024-23263
- CVE-2024-23280
- CVE-2024-23284
- CVE-2024-54658
- CVE-2024-27859
Frequently Asked Questions
What is the severity of CVE-2023-48795?
CVE-2023-48795 has been classified as a high severity vulnerability affecting the integrity of the SSH protocol.
How do I fix CVE-2023-48795?
To fix CVE-2023-48795, upgrade to the recommended versions of affected software such as Paramiko 3.4.0 or higher, and ensure all SSH implementations are updated accordingly.
What types of software are affected by CVE-2023-48795?
CVE-2023-48795 impacts various SSH implementations including Paramiko, OpenSSH, PuTTY, and several other cryptographic libraries.
Can CVE-2023-48795 be exploited remotely?
Yes, CVE-2023-48795 can be exploited remotely by attackers during the SSH handshake process.
What is the nature of the attack described in CVE-2023-48795?
CVE-2023-48795 refers to a prefix truncation attack, which compromises the integrity of the SSH secure channel.