Impact
Key exchange performed by the EMR SSH helper commands in Amazon AWS CLI lacks entity authentication. The vulnerability allows a man‑in‑the‑middle attacker positioned between the client and the EMR cluster to intercept SSH sessions and file transfers. The weakness rests on CWE‑322, which is an authentication bypass affecting confidentiality of data in transit.
Affected Systems
AWS customers using the AWS Command Line Interface v1 before 1.45.28 or v2 before 2.35.3 are affected. The issue is present in all previous releases of the CLI that support EMR SSH helper commands.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate impact risk. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The likely attack vector requires an attacker to place themselves on the network path between the client and the EMR cluster endpoint. Successful exploitation would allow interception of encrypted SSH traffic, enabling credential theft or data tampering.
OpenCVE Enrichment
Github GHSA