Researchers disclosed the Terrapin attack, a man-in-the-middle flaw in the SSH transport protocol tracked as CVE-2023-48795, that can corrupt the handshake and strip or disable negotiated security features. The attack exploits sequence number manipulation and prefix truncation in the SSH Binary Packet Protocol, affecting connections that use ChaCha20-Poly1305 and certain CBC with Encrypt-then-MAC configurations. The issue impacts OpenSSH before 9.6 and a broad set of SSH clients, servers, libraries, and products; researchers reported that 77% of Internet-exposed SSH servers supported at least one vulnerable mode and 57% preferred one.
The disclosure also highlighted implementation-specific flaws in AsyncSSH—CVE-2023-46445 and CVE-2023-46446—that could enable more severe outcomes, including redirecting a victim into an attacker-controlled shell account under the right conditions. Ruhr University Bochum researchers released technical details, proof-of-concept code, and a scanner after coordinated vendor fixes, while maintainers shipped updates including OpenSSH 9.6, PuTTY 0.8, libssh 0.10.6/0.9.8, and AsyncSSH 2.14.1/2.14.2. Defenders were urged to patch affected software and, where possible, disable vulnerable cipher modes in favor of safer options such as AES-GCM.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The Terrapin attack was tracked as CVE-2023-48795, covering the SSH transport protocol weakness that can allow integrity-check bypass and downgrade of negotiated security features in affected implementations.
Alongside disclosure, the researchers published the Terrapin technical paper as well as proof-of-concept code and a scanner, providing detailed information on the attack and affected configurations.
Researchers publicly revealed Terrapin, a man-in-the-middle prefix truncation attack against SSH that can weaken or remove negotiated security protections during the handshake under specific cipher configurations.
Affected projects issued updates to address Terrapin and related implementation flaws, including OpenSSH 9.6, PuTTY 0.8, libssh 0.10.6 and 0.9.8, and AsyncSSH 2.14.1 and 2.14.2.
Researchers from Ruhr University Bochum privately reported the Terrapin SSH weakness to affected vendors in October 2023, beginning coordinated remediation before public release.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcetheregister.com
Open sourcearstechnica.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.