CVE-2024-41909
published 2024-08-12CVE-2024-41909: Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept…
PriorityP433medium5.9CVSS 3.1
AVNACHPRNUINSUCNIHAN
EPSS
0.58%
43.7th percentile
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mina_sshd | <= 2.11.0 | — |
| debian | libmina-sshd-java | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
ghsa5.9MEDIUM
osv5.9MEDIUM
vendor_debian5.9LOW
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache MINA SSHD: integrity check bypass
osv·2024-08-12·CVSS 5.9
CVE-2024-41909 [MEDIUM] Apache MINA SSHD: integrity check bypass
Apache MINA SSHD: integrity check bypass
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
GHSA
Apache MINA SSHD: integrity check bypass
ghsa·2024-08-12·CVSS 5.9
CVE-2024-41909 [MEDIUM] CWE-354 Apache MINA SSHD: integrity check bypass
Apache MINA SSHD: integrity check bypass
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Mina SSHD) — CVE-2024-41909
vendor_oracle·2025-10-15·CVSS 5.9
CVE-2024-41909 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Mina SSHD) — CVE-2024-41909
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Apache Mina SSHD) vulnerability
CVE: CVE-2024-41909
CVSS: 5.9
Protocol: SSH
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) — CVE-2024-41909
vendor_oracle·2024-10-15·CVSS 5.9
CVE-2024-41909 [MEDIUM] Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) — CVE-2024-41909
Oracle Oracle Retail Applications Risk Matrix: Internal Operations (Apache Mina SSHD) vulnerability
CVE: CVE-2024-41909
CVSS: 5.9
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Red Hat
mina-sshd: integrity check bypass vulnerability
vendor_redhat·2024-08-12·CVSS 5.9
CVE-2024-41909 [MEDIUM] CWE-354 mina-sshd: integrity check bypass vulnerability
mina-sshd: integrity check bypass vulnerability
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which
some security features have been downgraded or disabled, aka a Terrapin
attack
The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
A flaw was found
Debian
CVE-2024-41909: libmina-sshd-java - Like many other SSH implementations, Apache MINA SSHD suffered from the issue th...
vendor_debian·2024·CVSS 5.9
CVE-2024-41909 [MEDIUM] CVE-2024-41909: libmina-sshd-java - Like many other SSH implementations, Apache MINA SSHD suffered from the issue th...
Like many other SSH implementations, Apache MINA SSHD suffered from the issue that is more widely known as CVE-2023-48795. An attacker that can intercept traffic between client and server could drop certain packets from the stream, potentially causing client and server to consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack The mitigations to prevent this type of attack were implemented in Apache MINA SSHD 2.12.0, both client and server side. Users are recommended to upgrade to at least this version. Note that both the client and the server implementation must have mitigations applied against this issue, otherwise the connection may still be affected.
Scope: local
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-08-12
Published