CVE-2023-48795
CVSS 5.9 MEDIUM: the SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows… EPSS 93% (100th percentile).
Vulnerabilities & Exploits
PAN‑OS and Prisma SD‑WAN ION devices are affected by Terrapin (CVE-2023-48795). An attacker intercepting SSH traffic can downgrade client connections to force weaker client-auth algorithms and expose administrative sessions; vendor rates severity Medium.
1 source · Mar 10
CVSS 5.9 MEDIUM: the SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows… EPSS 93% (100th percentile).
Palo Alto Networks Advisories
CVE-2023-48795 Impact of Terrapin SSH Attack
The Terrapin attack allows an attacker with the ability to intercept SSH traffic on affected Palo Alto Networks products (through machine-in-the-middle or MitM attacks) to downgrade connection securit...
originalVendor digest: Palo Alto Networks
Part of the PlainSec briefing for 2026-03-10
Every edition of this story: PAN‑OS, Prisma SD‑WAN SSH Downgrade Exposes Admin Sessions