Abstract
A vulnerability allows remote attackers to downgrade the integrity protection of SSH connections via a susceptible version of QSAN operating systems.
This vulnerability, together with several outdated third-party components identified during vulnerability scanning, has been fixed in the releases listed below.
Applied to
| Product | Severity | Fixed Release Availability |
| QSM | Moderate | 3.5.3 |
| XEVO | Moderate | 3.2.1 |
| SANOS | Moderate | 4.2.1 |
Mitigation
Upgrade the firmware to the latest version. If you need immediate assistance, please contact QSAN technical support via https://www.qsan.com/en/technical_support.
Detail
CVE-2023-48795
Severity: Moderate
CVSS3 Base Score: 5.9
CVSS3 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The SSH transport protocol with certain OpenSSH extensions allows remote attackers to bypass integrity checks such that some packets are omitted from the extension negotiation message, and a client and server may consequently end up with a connection for which some security features have been downgraded or disabled, aka a Terrapin attack.
The following components were also updated in the same releases: OpenSSL 1.1.1za, PHP 8.2.20, Apache HTTP Server 2.4.60, removal of the Python service used by xmirror, mDNS/Bonjour disabled by default, and TLS 1.0/1.1 disabled.