« Volver al listado

Wolfssh

Wolfssh: vulnerabilidades y CVE

Wolfssh tiene 7 vulnerabilidades publicadas, 5 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses5
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-0930Baja (2.3)0.17%—20 abr 2026
Potential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of bounds read after establishing a connection which would leak the…
CVE-2025-15382Media (5.1)0.35%—6 ene 2026
A heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue via crafted SCP path input containing '/./' sequences, resulting in a…
CVE-2025-14942Crítica (9.4)0.39%—6 ene 2026
wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or trick the client into skipping user authentication. This affects client…
CVE-2025-11625Crítica (9.4)0.43%—21 oct 2025
Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients credentials.
CVE-2025-11624Baja (1.8)0.37%—21 oct 2025
Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or file descriptor size, but smaller than max handle size allowed.
CVE-2024-2873Crítica (9.1)0.62%—25 mar 2024
A vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first performing user authentication, resulting in unauthorized access.
CVE-2022-32073Crítica (9.8)1.9%—13 jul 2022
WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1078 Valid Accounts2
  2. T1203 Exploitation for Client Execution2

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.