FlawAtlas
Search the atlas
USN-7292-1 Not scored

Several security issues were fixed in Dropbear

Manfred Kaiser discovered that Dropbear through 2020.81 does not properly check the available authentication methods in the client-side SSH code. An attacker could use this vulnerability to gain unauthorized access to remote systems. (CVE-2021-36369) Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that the SSH transport protocol implementation in Dropbear had weak integrity checks. An attacker could use this vulnerability to bypass security features like encryption and integrity checks. (CVE-2023-48795)

Exploit probability Not scored
Published February 25, 2025
Required by Not available
Last source change April 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:22.04:LTS dropbear

3 explicit affected versions

Ubuntu:Pro:18.04:LTS dropbear

2 explicit affected versions

Ubuntu:Pro:20.04:LTS dropbear

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-7292-1

Manfred Kaiser discovered that Dropbear through 2020.81 does not properly check the available authentication methods in the client-side SSH code. An attacker could use this vulnerability to gain unauthorized access to remote systems. (CVE-2021-36369) Fabian Bäumer, Marcus Brinkmann, and Jörg Schwenk discovered that the SSH transport protocol implementation in Dropbear had weak integrity checks. An attacker could use this vulnerability to bypass security features like encryption and integrity checks. (CVE-2023-48795)

View original source

05 / REFERENCES

Further evidence