Man-in-the-Middle Vulnerability in Libssh on Windows Systems
CVE-2025-14821
7.8HIGH
What is CVE-2025-14821?
A flaw has been identified in Libssh that may expose systems to local man-in-the-middle attacks. This vulnerability arises from an insecure default configuration on Windows environments, where the library can inadvertently load configuration files from the C:\etc directory. These files could potentially be created or altered by unprivileged local users, allowing for the manipulation of trusted host information and leading to security downgrades of SSH connections. This situation significantly jeopardizes the confidentiality, integrity, and availability of SSH communications.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Martin Grubhofer for reporting this issue.