Impact
The vulnerability lies in the libssh-based SFTP protocol handler of FFmpeg versions up to 9.0.2, where host key verification is omitted. This omission means an attacker can perform a man‑in‑the‑middle attack, impersonating an SFTP server and capturing passwords supplied in SFTP URLs, serving counterfeit media, or retrieving uploaded output. The flaw exposes sensitive authentication data and allows unauthorized modification of data streams, effectively compromising confidentiality, integrity, and availability of media transfers.
Affected Systems
Vendor: FFmpeg. Product: FFmpeg. Versions affected include all builds through 9.0.2 as identified by the CPE string cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*.*
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate severity level. No EPSS score was published, and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not yet been widely exploited. Nonetheless, the attack surface is remote, requiring network access to an SFTP endpoint. Attackers who control the network path or can spoof DNS/ARP could exploit the flaw to intercept credentials or tamper with media payloads. The lack of host key verification removes crucial authentication checks, making incident response more difficult and potentially leading to further compromise if the intercepted credentials are used against downstream systems.
OpenCVE Enrichment