Impact
The vulnerability is an improper certificate validation flaw in the asyncssh.connect function within Cochise's SSH Host Key Handler. By manipulating input, an attacker can trick the component into accepting forged or unauthorized SSH host certificates, thereby bypassing authentication and enabling unauthorized access to services. This issue falls under CWE-287 and CWE-295, representing authentication bypass and improper verification of cryptographic signatures. The CVSS score of 6.3 indicates a moderate severity that can compromise confidentiality and integrity of data when exploited.
Affected Systems
Vendor: andreashappe; Product: Cochise. All releases up to version 0.4.1 are affected. The flaw resides in the SSH Host Key Handler component of the asyncssh.connect function. Users must verify if their deployment uses an affected revision and apply updates accordingly.
Risk and Exploitability
The attack can be launched remotely and requires a high level of complexity, but the public exploitation effort is described as difficult. With a CVSS score of 6.3, the risk is moderate; however, the potential for unauthorized access encourages swift remediation. No field exploits have been reported and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is unavailable, so the current exploitation probability is unknown, yet the availability of a public exploit indicates a non‑zero risk if systems remain vulnerable.
OpenCVE Enrichment