← All Advisories

libssh Windows insecure config loading from C:\etc exposes SSH connections to local MITM and downgrade attacks

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2025-14821

Key Details

CVECVE-2025-14821
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-08-31
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productslibssh libssh and Red Hat hardened_images
Classified asCWE-427 (Uncontrolled Search Path Element)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
libsshlibssh
Red Hathardened_images
SubsystemsGeneral OT
SectorsMultiple

What to Know

A flaw was found in libssh. This vulnerability allows local man-in-the-middle attacks, security downgrades of SSH (Secure Shell) connections, and manipulation of trusted host information, posing a significant risk to the confidentiality, integrity, and availability of SSH communications via an insecure default configuration on Windows systems where the library automatically loads configuration files from the C:\etc directory, which can be created and modified by unprivileged local users. (NVD)

What to Do

Monitor libssh's and Red Hat's web pages for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-14821
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-14821