CVE-2023-48795: Terrapin Attack Silently Downgrades SSH Security via Packet Deletion
Researchers at Ruhr University Bochum disclosed the Terrapin attack in December 2023, registered as CVE-2023-48795, revealing a flaw in the SSH transport layer. The attack allows a network-positioned attacker to manipulate SSH's sequence numbers by injecting and deleting packets during the unencrypted handshake phase, without breaking any encryption. Because the sequence counter begins before authentication is active, both sides can be made to believe their message counts are aligned even though a packet has been silently removed. The most damaging deletion target is the SSH_MSG_EXT_INFO message, whose removal strips extension negotiation and can force a downgrade of security features both sides would otherwise have enabled. The attack does not expose passwords or plaintext data, but exploits the boundary between SSH's unauthenticated and authenticated phases — a reminder that cryptographic protocols often fail at the seams rather than at the cipher level.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in