https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-08
http://www.nessus.org/u?310ae51a
http://www.nessus.org/u?f145ebe7
http://seclists.org/fulldisclosure/2024/Mar/21
http://www.openwall.com/lists/oss-security/2023/12/18/3
http://www.openwall.com/lists/oss-security/2023/12/19/5
http://www.openwall.com/lists/oss-security/2023/12/20/3
http://www.openwall.com/lists/oss-security/2024/03/06/3
http://www.openwall.com/lists/oss-security/2024/04/17/8
https://access.redhat.com/security/cve/cve-2023-48795
http://www.nessus.org/u?a35e2d81
https://bugs.gentoo.org/920280
https://bugzilla.redhat.com/show_bug.cgi?id=2254210
https://bugzilla.suse.com/show_bug.cgi?id=1217950
https://crates.io/crates/thrussh/versions
https://filezilla-project.org/versions.php
https://forum.netgate.com/topic/184941/terrapin-ssh-attack
http://www.nessus.org/u?8f47b3df
https://github.com/NixOS/nixpkgs/pull/275249
https://github.com/PowerShell/Win32-OpenSSH/issues/2189
http://www.nessus.org/u?b66725b3
http://www.nessus.org/u?924f2de6
https://github.com/TeraTermProject/teraterm/releases/tag/v5.1
https://github.com/advisories/GHSA-45x7-px36-x8w8
https://github.com/apache/mina-sshd/issues/445
http://www.nessus.org/u?d5b1c9f3
https://github.com/connectbot/sshlib/compare/2.2.21...2.2.22
https://github.com/cyd01/KiTTY/issues/520
https://github.com/drakkan/sftpgo/releases/tag/v2.5.6
http://www.nessus.org/u?2ae86ebe
https://github.com/erlang/otp/releases/tag/OTP-26.2.1
http://www.nessus.org/u?45081311
https://github.com/hierynomus/sshj/issues/916
https://github.com/janmojzis/tinyssh/issues/81
http://www.nessus.org/u?54c769e6
https://github.com/libssh2/libssh2/pull/1291
http://www.nessus.org/u?5ccd77c1
http://www.nessus.org/u?c1f9a79b
https://github.com/mwiede/jsch/compare/jsch-0.2.14...jsch-0.2.15
https://github.com/mwiede/jsch/issues/457
https://github.com/mwiede/jsch/pull/461
http://www.nessus.org/u?67538349
https://github.com/openssh/openssh-portable/commits/master
https://github.com/paramiko/paramiko/issues/2337
http://www.nessus.org/u?6df2cbc1
http://www.nessus.org/u?bbf64630
https://github.com/proftpd/proftpd/blob/master/RELEASE_NOTES
https://github.com/proftpd/proftpd/issues/456
https://github.com/rapier1/hpn-ssh/releases
https://github.com/ronf/asyncssh/blob/develop/docs/changes.rst
https://github.com/ronf/asyncssh/tags
https://github.com/ssh-mitm/ssh-mitm/issues/165
https://github.com/warp-tech/russh/releases/tag/v0.40.2
https://gitlab.com/libssh/libssh-mirror/-/tags
https://groups.google.com/g/golang-announce/c/-n5WqVC18LQ
https://groups.google.com/g/golang-announce/c/qA3XtxvMUyg
https://help.panic.com/releasenotes/transmit5/
http://www.nessus.org/u?3d0a4afd
https://lists.debian.org/debian-lts-announce/2023/12/msg00017.html
https://lists.debian.org/debian-lts-announce/2024/01/msg00013.html
https://lists.debian.org/debian-lts-announce/2024/01/msg00014.html
https://lists.debian.org/debian-lts-announce/2024/04/msg00016.html
http://www.nessus.org/u?83d48d80
http://www.nessus.org/u?f07c065d
http://www.nessus.org/u?119baeb1
http://www.nessus.org/u?a7e4a6e4
http://www.nessus.org/u?6b8e8ad9
http://www.nessus.org/u?d2c3d18d
http://www.nessus.org/u?384ee1ef
http://www.nessus.org/u?050f310e
http://www.nessus.org/u?d2e6599c
http://www.nessus.org/u?62b48c22
http://www.nessus.org/u?d3376c89
http://www.nessus.org/u?cc6b9516
http://www.nessus.org/u?97ba4743
http://www.nessus.org/u?49877061
http://www.nessus.org/u?44195f2b
http://www.nessus.org/u?81558456
http://www.nessus.org/u?80455306
http://www.nessus.org/u?427febf1
https://matt.ucc.asn.au/dropbear/CHANGES
http://www.nessus.org/u?53e21f29
https://news.ycombinator.com/item?id=38684904
https://news.ycombinator.com/item?id=38685286
https://news.ycombinator.com/item?id=38732005
https://nova.app/releases/#v11.8
https://oryx-embedded.com/download/#changelog
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0002
https://roumenpetrov.info/secsh/#news20231220
https://security-tracker.debian.org/tracker/CVE-2023-48795
https://security-tracker.debian.org/tracker/source-package/libssh2
http://www.nessus.org/u?a98522a3
http://www.nessus.org/u?f10f1997
https://security.gentoo.org/glsa/202312-16
https://security.gentoo.org/glsa/202312-17
https://security.netapp.com/advisory/ntap-20240105-0004/
https://support.apple.com/kb/HT214084
https://thorntech.com/cve-2023-48795-and-sftp-gateway/
https://twitter.com/TrueSkrillor/status/1736774389725565005
https://ubuntu.com/security/CVE-2023-48795
https://winscp.net/eng/docs/history#6.2.2
https://www.bitvise.com/ssh-client-version-history#933
https://www.bitvise.com/ssh-server-version-history
https://www.chiark.greenend.org.uk/~sgtatham/putty/changes.html
https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update
https://www.debian.org/security/2023/dsa-5586
https://www.debian.org/security/2023/dsa-5588
http://www.nessus.org/u?64147fb2
http://www.nessus.org/u?831ef265
https://www.netsarang.com/en/xshell-update-history/
https://www.openssh.com/openbsd.html
https://www.openssh.com/txt/release-9.6
https://www.openwall.com/lists/oss-security/2023/12/18/2
https://www.openwall.com/lists/oss-security/2023/12/20/3
https://www.paramiko.org/changelog.html
http://www.nessus.org/u?7ee1cc85
http://www.nessus.org/u?cbbee1be
https://www.terrapin-attack.com
https://www.theregister.com/2023/12/20/terrapin_attack_ssh
https://www.vandyke.com/products/securecrt/history.txt
Severity: Medium
ID: 503259
Version: 1.1
Type: remote
Family: Tenable.ot
Published: 5/27/2025
Updated: 5/27/2025
Supported Sensors: Tenable OT Security
Risk Factor: Medium
Score: 6.1
Risk Factor: Medium
Base Score: 5.9
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CPE: cpe:/o:abb:sw_firmware, cpe:/o:abb:arm600_firmware
Required KB Items: Tenable.ot/ABB
Exploit Ease: No known exploits are available
Patch Publication Date: 12/18/2023
Vulnerability Publication Date: 12/18/2023
CVE: CVE-2023-48795
CWE: 354
ICSA: 25-105-08