Inadequate Encryption Strength in Apache Mina SSHD - CVE-2024-41909

 

Inadequate Encryption Strength in Apache Mina SSHD - CVE-2024-41909

Published: August 12, 2024


Vulnerability identifier: #VU95799
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-41909
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform MitM attack.

The vulnerability exists due to incorrect implementation of the SSH Binary Packet Protocol (BPP), which mishandles the handshake phase and the use of sequence numbers. A remote attacker can perform MitM attack and delete the SSH2_MSG_EXT_INFO message sent before authentication starts, allowing the attacker to disable a subset of the keystroke timing obfuscation features and perform "Terrapin attack".


Affected software

Apache Mina SSHD
DB2 Data Management Console
IBM Business Automation Manager Open Editions
IBM Watson Knowledge Catalog in Cloud Pak for Data
IBM Sterling B2B Integrator
Oracle Middleware Common Libraries and Tools
Oracle Retail Customer Management and Segmentation Foundation

How to mitigate CVE-2024-41909

Install updates from vendor's website.

Apache Mina SSHD - update to 2.12.0
DB2 Data Management Console - update to 3.1.13
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.3
IBM Sterling B2B Integrator - addressed in versions 6.1.2.7, 6.2.0.4
IBM Business Automation Manager Open Editions - update to 8.0.7

External References

Related Security Bulletins