vciy

CVE-2023-48795 · Terrapin

INDEX BUILT · 2026-09-20

No source can show you its own past. This one can.

Print this page to keep the view as it stands on this date. Everything hidden behind a disclosure opens, and every receipt prints with its value.

The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass…

CVE-2023-487953 of 4 sources documented this
56

rank 56 = 29 + 15 + 2 + 10 + 0

rank@v1 · this cycle

Someone is already using it

CISA KEV catalog · public proof-of-concept · FIRST EPSS

EPSS 0.93305  ·  without this subject the record ranks 27

What it costs you if it fires

NVD CVSS base score, then the CNA's own

CVSS 5.9, from NVD  ·  without this subject the record ranks 41

It is getting worse, not staying still

FIRST EPSS series, rescorings and bad loads removed

rose on 2025-08-04  ·  without this subject the record ranks 54

How much of the world it touches

NVD CPE configurations

20 products in the CPE ranges  ·  without this subject the record ranks 46

Someone else already set the date

CISA KEV remediation due date

no CISA due date  ·  without this subject the record ranks 56

Unaudited dollar value2 of 3 inputs carry a receipt
Exposure$2.85Mover the next 30 days, if this record is yours
Movement+$301,000on 2026-03-04, the last material move, 4 months before this reading
Basisassumeda published average, not your estate

$2.85M = $4.99M incident cost x 0.6121449559255632 exposure x 0.93305 likelihood

udv@v1 · unaudited · wrong for you until you say what you run

$4.99M is the cost of a breach that happened, from IBM Cost of a Data Breach Report 2026, global average. It is not the value of any asset of yours. That average already covers breaches of every severity, so scaling it by exposure understates a partial-impact record. That is an assumption, not a measurement. Your own asset value goes in the decision record.

Hindsight · the state

0.93305EPSSNOT IN KEVas of 2026-09-20
Severity5.9 MEDIUMreceipt
Harmunauthenticated · networkreceipt
Exploitationpublic proof-of-conceptreceipt
Defenseunaffected versions publishedreceipt
Movementdoubled within 72hreceipt
PLATEAU10Minimal movement since 2026-06-15, 23 days at 0.93, as of 2026-07-08. arc-rules@v1

Foresight · where to check next

No weakness class or product neighbourhood is held for this record, so this index cannot name anywhere to check next. That is an absence in the record, not a finding about the software.

Color is a claim, not decoration:the hostile worldthe defenseno signal

Check a version against this record

A deterministic range check against the ranges this record publishes. It tells you where a version sits in the record, not whether your deployment is exploitable. No account needed.

Watch this record

Matches your own product list against every record this index holds, and tells you when one of them moves.

What counts as a move

Set up a watchlist (needs a Practitioner account)

Record your call

Keep your verdict, your reason and the evidence together. The record takes its date when you save it.

AcceptDeferPatch by…Not affectedMitigated

Choose your verdict, then sign in or use an email link. Your first 100 records are free. Evidence is frozen when the record is created.

Private to your organization unless you share it. Put the proof link in your ticket so a reviewer can inspect the basis for your call. See how decision records work.

Harm, if it fires from the vector and the weakness

Written for the ticket you're about to file.

Reachnetwork-reachable · no privileges required · no user interaction · high attack complexityreceipt
ImpactComplete integrity lossreceipt
Scored fromCVSS v3.1 · NVD's vectorreceipt
Weakness classCWE-354 Improper Validation of Integrity Check Valuereceipt
Published consequencesCWE-354: Integrity, Other: Modify Application Data, Other; Integrity, Other: Other; Non-Repudiation, Other: Hide Activities, Other[email protected]

CISA KEV & Federal Remediation Deadline from the record and CISA

The fix, and how long it's been waiting.

First unaffected version, by branchlibssh 0.10.6; nova 11.8; openssh 9.6; putty 0.80; securecrt 9.4.3; ssh client 9.33receipt
Patch available sinceNo dated patch-availability record in held sources. The index holds reference URLs without dates and only the current revision of the CVE record, so the day a fix first existed cannot be derived. Only the versions it landed in.

Exploit Status & Known PoCs a ladder, not a score

Current rung: Proof-of-concept published · 4 public repositories, 2025-01-08.

  • RUNG 1Nothing observed in held sources
  • RUNG 2Proof-of-concept published · 4 public repositories2025-01-08receipt
  • RUNG 3Exploited in the wild · CISA KEV listed
  • RUNG 4Ransomware campaign use known

Authority who says so

CVSS, NVD5.9 MEDIUMreceipt
Exploit probability0.93305 · top 0.17% of all CVEsreceipt
Blast breadth19 products across 16 vendorsderived
Assigned bymitrereceipt
Recorded changes196 · last 18 Sep 2026derived

Affected & Fixed Versions as published

Named in the CPE rangesOpenbsd openssh; Putty; Panic transmit; and 16 morereceipt
Published rangesopenbsd openssh < 9.6; putty < 0.80; filezilla-project filezilla client < 3.66.4; panic transmit 5 < 5.10.4receipt
Show all 20 published ranges
openbsd openssh < 9.6
putty < 0.80
filezilla-project filezilla client < 3.66.4
panic transmit 5 < 5.10.4
panic nova < 11.8
roumenpetrov pkixssh < 14.4
winscp < 6.2.2
bitvise ssh client < 9.33
bitvise ssh server < 9.32
lancom-systems lcos <= 3.66.4
lancom-systems lcos sx 4.20
lancom-systems lcos sx 5.20
vandyke securecrt < 9.4.3
libssh < 0.10.6
net-ssh 7.2.0
ssh2 project ssh2 <= 1.11.0
proftpd <= 1.3.8b
freebsd <= 12.4
crates thrussh < 0.35.1
tera term project tera term <= 5.1

A rung lights from a row in the index, never from an assessment. "Held sources" is the true scope of the claim: this index reads the CVE record, NVD, CISA KEV, FIRST's EPSS and public proof-of-concept repositories, and it does not observe attacks.

Did this affect your environment?Answering needs an account.

What it is stated by the CNA

Terrapin is the common name for CVE-2023-48795. The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack. This occurs because the SSH Binary Packet Protocol (BPP), implemented by these extensions, mishandles the handshake phase and mishandles use of sequence numbers. For example, there is an effective attack against SSH's use of ChaCha20-Poly1305 (and CBC with Encrypt-then-MAC). cve-aliases@2026-08-27

Read the rest of the CNA's description

The bypass occurs in [email protected] and (if CBC is used) the [email protected] MAC algorithms. This also affects Maverick Synergy Java SSH API before 3.1.0-SNAPSHOT, Dropbear through 2022.83, Ssh before 5.1.1 in Erlang/OTP, PuTTY before 0.80, AsyncSSH before 2.14.2, golang.org/x/crypto before 0.17.0, libssh before 0.10.6, libssh2 through 1.11.0, Thorn Tech SFTP Gateway before 3.4.6, Tera Term before 5.1, Paramiko before 3.4.0, jsch before 0.2.15, SFTPGo before 2.5.6, Netgate pfSense Plus through 23.09.1, Netgate pfSense CE through 2.7.2, HPN-SSH through 18.2.0, ProFTPD before 1.3.8b (and before 1.3.9rc2), ORYX CycloneSSH before 2.3.4, NetSarang XShell 7 before Build 0144, CrushFTP before 10.6.0, ConnectBot SSH library before 2.2.22, Apache MINA sshd through 2.11.0, sshj through 0.37.0, TinySSH through 20230101, trilead-ssh2 6401, LANCOM LCOS and LANconfig, FileZilla before 3.66.4, Nova before 11.8, PKIX-SSH before 14.4, SecureCRT before 9.4.3, Transmit5 before 5.10.4, Win32-OpenSSH before 9.5.0.0p1-Beta, WinSCP before 6.2.2, Bitvise SSH Server before 9.32, Bitvise SSH Client before 9.33, KiTTY through 0.76.1.13, the net-ssh gem 7.2.0 for Ruby, the mscdex ssh2 module before 1.15.0 for Node.js, the thrussh library before 0.35.1 for Rust, and the Russh crate before 0.40.2 for Rust.

NVD's analysis a second authority

severity
5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
weakness
CWE-354
affected versions
openbsd openssh < 9.6; putty < 0.80; filezilla-project filezilla client < 3.66.4; and 17 more, listed in full below
also scored by
5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

check it yourself chiark.greenend.org.uk matt.ucc.asn.au github.com netsarang.com paramiko.org openssh.com +14 morereceipt

Dated events

2023-12-29EPSS moved 0.02 to 0.362026-06-15EPSS moved 0.52 to 0.93

Movement the material steps

19 Dec 20230.01261
29 Dec 20230.35876 · crossed 0.10
10 Jan 20240.65657 · crossed 0.50
17 Apr 20240.94074 · crossed 0.90
17 Mar 20250.54879 · crossed 0.90 · scoring model v2025.03.14
18 Mar 20250.66241
19 Mar 20250.79243
20 Mar 20250.69008
23 Mar 20250.81243
2 Apr 20250.67861
7 Apr 20250.5638
15 Apr 20250.74304
30 Apr 20250.56918
1 May 20250.43795 · crossed 0.50
4 May 20250.60016 · crossed 0.50
9 May 20250.48384 · crossed 0.50
15 May 20250.77161 · crossed 0.50
1 Jun 20250.67021
18 Jun 20250.77369
3 Jul 20250.59547
16 Jul 20250.75226
17 Jul 20250.64791
28 Jul 20250.76026
1 Aug 20250.65108
4 Aug 20250.77273
8 Aug 20250.6447
19 Aug 20250.77264
1 Sep 20250.57191
4 Sep 20250.69822
1 Oct 20250.56077
17 Oct 20250.68029
21 Oct 20250.56542
21 Dec 20250.66834
1 Jan 20260.47891 · crossed 0.50
4 Jan 20260.57768 · crossed 0.50
1 Feb 20260.47986 · crossed 0.50
4 Feb 20260.5901 · crossed 0.50
1 Mar 20260.47986 · crossed 0.50
4 Mar 20260.57856 · crossed 0.50
15 Jun 20260.93305 · crossed 0.90 · scoring model v2026.06.15
8 Jul 20260.93305

This score more than doubled inside 72 hours. Both observations are in the full history below.

Show all 193 observations
19 Dec 20230.01261
20 Dec 20230.00899
23 Dec 20230.01153
28 Dec 20230.01627
29 Dec 20230.35876
30 Dec 20230.43479
10 Jan 20240.65657
24 Jan 20240.69435
22 Feb 20240.71637
26 Mar 20240.69474
17 Apr 20240.94074
21 Apr 20240.93522
28 Apr 20240.93944
30 Apr 20240.96225
22 May 20240.95994
30 May 20240.95901
9 Jun 20240.96168
24 Jun 20240.96252
13 Jul 20240.96574
26 Jul 20240.96466
16 Aug 20240.96533
20 Sep 20240.96467
13 Oct 20240.96536
24 Oct 20240.96252
17 Nov 20240.96288
29 Nov 20240.96280
17 Dec 20240.94609
24 Dec 20240.94860
19 Jan 20250.95483
26 Feb 20250.95474
11 Mar 20250.95381
17 Mar 20250.54879
18 Mar 20250.66241
19 Mar 20250.79243
20 Mar 20250.69008
23 Mar 20250.81243
25 Mar 20250.79573
27 Mar 20250.86444
28 Mar 20250.7768
29 Mar 20250.85817
30 Mar 20250.7768
31 Mar 20250.78025
2 Apr 20250.67861
3 Apr 20250.69616
5 Apr 20250.60138
6 Apr 20250.62212
7 Apr 20250.5638
13 Apr 20250.58568
15 Apr 20250.74304
17 Apr 20250.74273
18 Apr 20250.81272
19 Apr 20250.73874
20 Apr 20250.69098
21 Apr 20250.70792
22 Apr 20250.69616
28 Apr 20250.70755
30 Apr 20250.56918
1 May 20250.43795
4 May 20250.60016
6 May 20250.58568
7 May 20250.60016
9 May 20250.48384
11 May 20250.46788
15 May 20250.77161
16 May 20250.82815
19 May 20250.81737
20 May 20250.7644
21 May 20250.81359
23 May 20250.8524
24 May 20250.8612
25 May 20250.85203
27 May 20250.84841
28 May 20250.78727
29 May 20250.73148
1 Jun 20250.67021
4 Jun 20250.73656
12 Jun 20250.7208
14 Jun 20250.73616
15 Jun 20250.74591
17 Jun 20250.71895
18 Jun 20250.77369
19 Jun 20250.77106
20 Jun 20250.79456
25 Jun 20250.80705
1 Jul 20250.6772
3 Jul 20250.59547
4 Jul 20250.64931
7 Jul 20250.66819
16 Jul 20250.75226
17 Jul 20250.64791
18 Jul 20250.6127
19 Jul 20250.64791
22 Jul 20250.67991
23 Jul 20250.70714
26 Jul 20250.74413
28 Jul 20250.76026
29 Jul 20250.79991
30 Jul 20250.79173
31 Jul 20250.75753
1 Aug 20250.65108
3 Aug 20250.62834
4 Aug 20250.77273
5 Aug 20250.72252
6 Aug 20250.67729
8 Aug 20250.6447
11 Aug 20250.61286
16 Aug 20250.63432
17 Aug 20250.66361
18 Aug 20250.63432
19 Aug 20250.77264
20 Aug 20250.75161
21 Aug 20250.74635
26 Aug 20250.7623
30 Aug 20250.69015
1 Sep 20250.57191
4 Sep 20250.69822
9 Sep 20250.63735
17 Sep 20250.65058
30 Sep 20250.68889
1 Oct 20250.56077
4 Oct 20250.65094
5 Oct 20250.64055
12 Oct 20250.6242
13 Oct 20250.59563
17 Oct 20250.68029
18 Oct 20250.61281
20 Oct 20250.59563
21 Oct 20250.56542
24 Oct 20250.61406
28 Oct 20250.62986
31 Oct 20250.58241
1 Nov 20250.51646
4 Nov 20250.58241
6 Nov 20250.61192
9 Nov 20250.55964
12 Nov 20250.52818
18 Nov 20250.50546
21 Nov 20250.52818
22 Nov 20250.58677
25 Nov 20250.61707
27 Nov 20250.65295
1 Dec 20250.53167
4 Dec 20250.60866
5 Dec 20250.579
8 Dec 20250.55964
10 Dec 20250.57768
18 Dec 20250.64958
21 Dec 20250.66834
22 Dec 20250.62547
24 Dec 20250.57768
1 Jan 20260.47891
3 Jan 20260.49145
4 Jan 20260.57768
18 Jan 20260.57856
21 Jan 20260.5901
27 Jan 20260.57856
1 Feb 20260.47986
4 Feb 20260.5901
6 Feb 20260.57856
10 Feb 20260.62629
15 Feb 20260.5901
16 Feb 20260.57856
17 Feb 20260.62629
18 Feb 20260.57856
1 Mar 20260.47986
4 Mar 20260.57856
21 Mar 20260.66908
23 Mar 20260.62629
25 Mar 20260.65372
27 Mar 20260.62629
28 Mar 20260.57856
29 Mar 20260.53027
1 Apr 20260.5673
21 Apr 20260.61084
22 Apr 20260.58603
23 Apr 20260.53559
25 Apr 20260.58603
5 May 20260.53559
13 May 20260.52606
16 May 20260.50714
22 May 20260.52606
25 May 20260.53826
27 May 20260.52606
29 May 20260.54214
8 Jun 20260.52998
12 Jun 20260.51662
15 Jun 20260.93305
21 Jun 20260.94072
23 Jun 20260.93305
25 Jun 20260.94072
26 Jun 20260.93305
2 Jul 20260.9378
8 Jul 20260.93305

193 observations held. A highlighted step crossed a promotion threshold. A step marked with a scoring model moved because the instrument was replaced, not because the vulnerability changed. receipt

The full biography

EPSS 0.93305Published2023-12-18Public PoC2025-01-08Index as of2026-07-08

Exploit probability more than doubled between 2023-12-28 and 2023-12-29 (0.01627 → 0.35876) and the record had been public for 2 years, 6 months when this index was last written.

Published 2023-12-18 receipt · Public PoC 2025-01-08 receipt · Index as of 2026-07-08 derived

Siblings and hubs

Records related to this one

Browse the index from here

These are index-wide views, not findings about CVE-2023-48795.

What usually comes next

Everything above needs no account. What is below is work: assembling it, scoping it to your estate, watching it, and handing it to someone else.

Everything on this page is free. Public data. Withholding it protects nothing.