« Volver al listado

CVE-2026-48859

Estado: ModificadaMedia (6.3)—

Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.

When the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This timing difference is detectable in a single authentication attempt and allows an unauthenticated attacker to distinguish valid from invalid usernames.

Leer descripción completaMostrar menos

The user_passwords and password options are documented as intended for test purposes; the recommended alternative is pwdfun, which is not affected by this vulnerability.

This vulnerability is associated with program files lib/ssh/src/ssh_auth.erl and lib/ssh/src/ssh_options.erl.

This issue affects OTP from OTP 29.0 before OTP 29.0.2, corresponding to ssh from 6.0 before 6.0.1.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-48859",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-48859",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T16:19:16.914933Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6.3,
          "Automatable": "NOT_DEFINED",
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "NONE",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "LOW",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "vendor": "Erlang",
          "modules": [
            "ssh_auth",
            "ssh_options"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "version": "29.0",
              "lessThan": "29.0.2",
              "versionType": "otp"
            }
          ],
          "packageURL": "pkg:software-id/erlang.org/otp",
          "packageName": "otp",
          "programFiles": [
            "lib/ssh/src/ssh_auth.erl",
            "lib/ssh/src/ssh_options.erl"
          ],
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "ssh_auth:check_password/3"
            },
            {
              "name": "ssh_options:get_password_option/2"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "modules": [
            "ssh_auth",
            "ssh_options"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "version": "6.0",
              "lessThan": "6.0.1",
              "versionType": "otp"
            }
          ],
          "packageURL": "pkg:otp/ssh?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%20https:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
          "packageName": "ssh",
          "programFiles": [
            "src/ssh_auth.erl",
            "src/ssh_options.erl"
          ],
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "ssh_auth:check_password/3"
            },
            {
              "name": "ssh_options:get_password_option/2"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
          ],
          "repo": "https://github.com/erlang/otp",
          "vendor": "Erlang",
          "modules": [
            "ssh_auth",
            "ssh_options"
          ],
          "product": "OTP",
          "versions": [
            {
              "status": "affected",
              "version": "032d1bc9491a3975c68faf9bc7776115d6ae3005",
              "lessThan": "c342092ef4b369bb409d5b71ac8fd83bab74aedf",
              "versionType": "git"
            }
          ],
          "packageURL": "pkg:github/erlang/otp",
          "packageName": "erlang/otp",
          "programFiles": [
            "lib/ssh/src/ssh_auth.erl",
            "lib/ssh/src/ssh_options.erl"
          ],
          "collectionURL": "https://github.com",
          "defaultStatus": "unaffected",
          "programRoutines": [
            {
              "name": "ssh_auth:check_password/3"
            },
            {
              "name": "ssh_options:get_password_option/2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-10T16:17:12.373",
  "references": [
    {
      "url": "https://cna.erlef.org/cves/CVE-2026-48859.html",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/erlang/otp/commit/c342092ef4b369bb409d5b71ac8fd83bab74aedf",
      "tags": [
        "Patch"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://github.com/erlang/otp/security/advisories/GHSA-3w6p-vwhf-wvp4",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://osv.dev/vulnerability/EEF-CVE-2026-48859",
      "tags": [
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    },
    {
      "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions",
      "tags": [
        "Product"
      ],
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
      "description": [
        {
          "lang": "en",
          "value": "CWE-208"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated remote username enumeration via timing side-channel in password authentication.\n\nWhen the SSH daemon is configured with the user_passwords or password option, ssh_auth:check_password/3 performs a PBKDF2-SHA256 computation with 600,000 iterations (~300ms) for valid usernames, but returns immediately (~0ms) for invalid usernames via the ssh_options:get_password_option/2 path. This timing difference is detectable in a single authentication attempt and allows an unauthenticated attacker to distinguish valid from invalid usernames.\n\nThe user_passwords and password options are documented as intended for test purposes; the recommended alternative is pwdfun, which is not affected by this vulnerability.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_auth.erl and lib/ssh/src/ssh_options.erl.\n\nThis issue affects OTP from OTP 29.0 before OTP 29.0.2, corresponding to ssh from 6.0 before 6.0.1."
    }
  ],
  "lastModified": "2026-09-08T01:17:31.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
              "versionEndExcluding": "29.0.2",
              "versionStartIncluding": "29.0"
            },
            {
              "criteria": "cpe:2.3:a:erlang:erlang\\/ssh:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0BF9A1F8-83F5-4BEB-A972-3AF5B15947EF",
              "versionEndExcluding": "6.0.1",
              "versionStartIncluding": "6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
}