Vulnerability Description
OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing attacks against keystroke entry could occur.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2024/07/03/6
- http://www.openwall.com/lists/oss-security/2024/07/23/4
- http://www.openwall.com/lists/oss-security/2024/07/23/6
- http://www.openwall.com/lists/oss-security/2024/07/28/3
- https://crzphil.github.io/posts/ssh-obfuscation-bypass/
- https://lists.mindrot.org/pipermail/openssh-unix-announce/2024-July/000158.html
- https://news.ycombinator.com/item?id=41508530
- https://security.netapp.com/advisory/ntap-20240712-0004/
- https://www.openssh.com/txt/release-9.8
- https://www.openwall.com/lists/oss-security/2024/07/02/1
- http://seclists.org/fulldisclosure/2024/Sep/33
- http://www.openwall.com/lists/oss-security/2024/07/03/6
- http://www.openwall.com/lists/oss-security/2024/07/23/4
- http://www.openwall.com/lists/oss-security/2024/07/23/6
- http://www.openwall.com/lists/oss-security/2024/07/28/3
FAQ
What is CVE-2024-39894?
CVE-2024-39894 is a vulnerability with a CVSS score of 7.5 (HIGH). OpenSSH 9.5 through 9.7 before 9.8 sometimes allows timing attacks against echo-off password entry (e.g., for su and Sudo) because of an ObscureKeystrokeTiming logic error. Similarly, other timing att...
How severe is CVE-2024-39894?
CVE-2024-39894 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-39894?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.