DNA View

High Severity Vulnerability

This vulnerability has been rated as High severity. Immediate action is recommended.

CVE-2025-22869

High
Low Medium High Critical
7.5
CVSS Score
Published: Feb 26, 2025
Last Modified: May 01, 2025

Vulnerability Description

SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
N
Attack Complexity
L
Privileges Required
N
User Interaction
N
Scope
U
Confidentiality
N
Integrity
N
Availability
H

Known Affected Software

34 configuration(s) from 1 vendor(s)

ssh
Version:
0.34.0
CPE:
cpe:2.3:a:go:ssh:0.34.0:*:*:*:*:go:*:*
ssh
Version:
0.29.0
CPE:
cpe:2.3:a:go:ssh:0.29.0:*:*:*:*:go:*:*
ssh
Version:
0.24.0
CPE:
cpe:2.3:a:go:ssh:0.24.0:*:*:*:*:go:*:*
ssh
Version:
0.31.0
CPE:
cpe:2.3:a:go:ssh:0.31.0:*:*:*:*:go:*:*
ssh
Version:
0.33.0
CPE:
cpe:2.3:a:go:ssh:0.33.0:*:*:*:*:go:*:*
ssh
Version:
0.25.0
CPE:
cpe:2.3:a:go:ssh:0.25.0:*:*:*:*:go:*:*
ssh
Version:
0.10.0
CPE:
cpe:2.3:a:go:ssh:0.10.0:*:*:*:*:go:*:*
ssh
Version:
0.9.0
CPE:
cpe:2.3:a:go:ssh:0.9.0:*:*:*:*:go:*:*
ssh
Version:
0.17.0
CPE:
cpe:2.3:a:go:ssh:0.17.0:*:*:*:*:go:*:*
ssh
Version:
0.21.0
CPE:
cpe:2.3:a:go:ssh:0.21.0:*:*:*:*:go:*:*
ssh
Version:
0.11.0
CPE:
cpe:2.3:a:go:ssh:0.11.0:*:*:*:*:go:*:*
ssh
Version:
0.27.0
CPE:
cpe:2.3:a:go:ssh:0.27.0:*:*:*:*:go:*:*
ssh
Version:
0.8.0
CPE:
cpe:2.3:a:go:ssh:0.8.0:*:*:*:*:go:*:*
ssh
Version:
0.16.0
CPE:
cpe:2.3:a:go:ssh:0.16.0:*:*:*:*:go:*:*
ssh
Version:
0.15.0
CPE:
cpe:2.3:a:go:ssh:0.15.0:*:*:*:*:go:*:*
ssh
Version:
0.13.0
CPE:
cpe:2.3:a:go:ssh:0.13.0:*:*:*:*:go:*:*
ssh
Version:
0.22.0
CPE:
cpe:2.3:a:go:ssh:0.22.0:*:*:*:*:go:*:*
ssh
Version:
0.1.0
CPE:
cpe:2.3:a:go:ssh:0.1.0:*:*:*:*:go:*:*
ssh
Version:
0.18.0
CPE:
cpe:2.3:a:go:ssh:0.18.0:*:*:*:*:go:*:*
ssh
Version:
0.23.0
CPE:
cpe:2.3:a:go:ssh:0.23.0:*:*:*:*:go:*:*
ssh
Version:
0.12.0
CPE:
cpe:2.3:a:go:ssh:0.12.0:*:*:*:*:go:*:*
ssh
Version:
0.28.0
CPE:
cpe:2.3:a:go:ssh:0.28.0:*:*:*:*:go:*:*
ssh
Version:
0.2.0
CPE:
cpe:2.3:a:go:ssh:0.2.0:*:*:*:*:go:*:*
ssh
Version:
0.4.0
CPE:
cpe:2.3:a:go:ssh:0.4.0:*:*:*:*:go:*:*
ssh
Version:
0.6.0
CPE:
cpe:2.3:a:go:ssh:0.6.0:*:*:*:*:go:*:*
ssh
Version:
0.19.0
CPE:
cpe:2.3:a:go:ssh:0.19.0:*:*:*:*:go:*:*
ssh
Version:
0.3.0
CPE:
cpe:2.3:a:go:ssh:0.3.0:*:*:*:*:go:*:*
ssh
Version:
0.30.0
CPE:
cpe:2.3:a:go:ssh:0.30.0:*:*:*:*:go:*:*
ssh
Version:
0.32.0
CPE:
cpe:2.3:a:go:ssh:0.32.0:*:*:*:*:go:*:*
ssh
Version:
0.14.0
CPE:
cpe:2.3:a:go:ssh:0.14.0:*:*:*:*:go:*:*
ssh
Version:
0.5.0
CPE:
cpe:2.3:a:go:ssh:0.5.0:*:*:*:*:go:*:*
ssh
Version:
0.7.0
CPE:
cpe:2.3:a:go:ssh:0.7.0:*:*:*:*:go:*:*
ssh
Version:
0.20.0
CPE:
cpe:2.3:a:go:ssh:0.20.0:*:*:*:*:go:*:*
ssh
Version:
0.26.0
CPE:
cpe:2.3:a:go:ssh:0.26.0:*:*:*:*:go:*:*
This vulnerability affects 34 software configuration(s). Ensure you patch all affected systems.

Available Security Patches

4 patches available from vendors

View All Patches
Oracle

CPUAPR2026

Oracle Critical Patch Update Advisory - April 2026

Severity
Critical
Released
Apr 21, 2026
Restart Required
Security Update
Microsoft

2025-Feb-CVE-2025-22869

CVE-2025-22869: Potential denial of service in golang.org/x/crypto

Severity
Unknown
Released
Oct 24, 2025
Security Update
Microsoft

2025-Mar-CVE-2025-22869

CVE-2025-22869: None

Severity
Unknown
Released
Sep 04, 2025
Security Update
SUSE

CVE-2025-22869

CVE-2025-22869

Severity
Unknown
Released
Feb 28, 2025
Security Update

Severity Details

7.5
out of 10.0
High

Weakness Type (CWE)

CWE-770

Allocation of Resources Without Limits or Throttling

Description
The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.
Exploit Likelihood
High
Typical Severity
Medium
Abstraction Level
Base

Key Information

Published Date
February 26, 2025