Vulnerability CVE-2023-48795 impacts the devices withOpenSSH before 9.6 of Juniper Networks Junos OS and Junos OS Evolved.
It allows a remote attacker to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka the Terrapin Attack.The most serious identified impact is that it lets an on-path attacker delete the SSH2_MSG_EXT_INFO message sent before authentication starts, allowing the attacker to disable a subset of the keystroke timing obfuscation features introduced in OpenSSH 9.5.
On
The OpenSSH version was upgraded to 9.7 to mitigate the issue.
The versions with the OpenSSH upgraded t0 9.7 are evo:24.2R2-EVO 21.4R3-S9 22.4R3-S4 23.2R2-S4 23.4R2-S4 24.2R1-S1 24.2R1-S2 24.2R2 24.3R1 24.4R1 24.4R2 25.1R1 25.2R1.
For more details on the CVE, please refer the below:
https://prsearch.juniper.net/problemreport/PR1781732
Version 1