SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Terrapin Alert (CVE-2023-48795): Safeguarding Against the Latest SSH Vulnerability

Terrapin Alert (CVE-2023-48795): Safeguarding Against the Latest SSH Vulnerability

In a recent revelation, a new vulnerability named Terrapin (CVE-2023-48795) has been identified in the Secure Shell (SSH) cryptographic network protocol. This vulnerability poses a serious threat to the integrity of SSH connections, impacting both clients and servers.

Jan 3, 2024By Charith GR2 min read

In a recent revelation, a new vulnerability named Terrapin (CVE-2023-48795) has been identified in the Secure Shell (SSH) cryptographic network protocol. This vulnerability poses a serious threat to the integrity of SSH connections, impacting both clients and servers.

SSH is a cryptographic network protocol designed to establish a secure and encrypted connection between two systems. Key Applications of SSH are Remote Login, Secure File Transfer, Tunneling and Port Forwarding.

Terrapin in Action: How It Works

Terrapin works by carefully adjusting sequence numbers during the handshake, allowing an attacker to remove messages from the client or server at the beginning of the secure channel without detection. The truncation can lead to the use of less secure client authentication algorithms and the deactivation of specific countermeasures against keystroke timing attacks.

The Terrapin Attack (CVE-2023-48795): Decrypting the Threat

Terrapin is a prefix truncation attack that manipulates sequence numbers during the handshake process. It compromises on the integrity of SSH channels, particularly when using encryption modes like ChaCha20-Poly1305 or CBC with Encrypt-then-MAC. The attack allows threat actors to downgrade public key algorithms for user authentication, disabling defenses against keystroke timing attacks in Open SSH 9.5.

A key prerequisite for Terrapin attack(CVE-2023-48795) is the need for attackers to be in adversary-in-the-middle(AitM) position, intercepting and modifying handshake exchange. A recent report by security threat monitoring platform Shadowserver indicates that almost 11 million SSH servers on the public web, constituting roughly 52% of all scanned samples, are vulnerable to Terrapin attacks.

Global Impact and Vulnerability Distribution

The significance of Shadowserver’s report is underscored by the widespread impact of Terrapin attacks. Most vulnerable systems were identified in the United States(3.3 million), followed by China(1.3 million), Germany(1 million), Russia(700,000), Singapore(390,000), and Japan(380,000).

Defensive Measures and Recommendations

To execute a Terrapin attack (CVE-2023-48795), threat actors need to perform a man-in-the-middle attack at the network layer, securing the connection with ChaCha20-Poly1305 or CBC with Encrypt-then-MAC. It’s recommended to use vulnerability scanners like  SanerNow to identify susceptible servers and clients. Additionally, applying updates to both clients and servers, is crucial to mitigate the effects of the Terrapin vulnerability.

SanerNow Vulnerability ManagementRisk Prioritization, and Patch Management detect and automatically fix vulnerabilities with risk-based remediation. With SanerNow, you can keep your systems updated and secure.

Featured Posts

Open Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests
Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

CVE Research

Squidbleed: A 29-Year-Old Squid Proxy Flaw That Leaks Cleartext HTTP Requests

Jun 23, 2026

Open AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure
AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

CVE Research

AryStinger Malware Leverages 4,300+ Legacy Routers to Establish Persistent Spy Infrastructure

AryStinger represents a calculated shift in IoT threat methodology, abandoning noisy, destructive payloads in favor of silent, long-term reconnaissance infrastructure. By exploiting unpatched, end-of-life routers and NAS devices through decade-old vulnerabilities, the threat operator has assembled a distributed fleet of over 4,300 Executor nodes capable of conducting parallelized DNS enumeration, port scanning, and service fingerprinting at scale, all while masking origin behind residential IP addresses. With active development ongoing and a potential operational timeline stretching back to 2024, AryStinger underscores a growing and underappreciated risk: forgotten edge hardware is not merely a compliance gap but exploitable infrastructure.

Jun 23, 2026

Open From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations
From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

CVE Research

From Emergence to Dominance: INC Ransomware Surpasses 830 Victims and Strengthens Its RaaS Operations

INC Ransomware has rapidly evolved into one of the most active ransomware-as-a-service (RaaS) operations in 2026, claiming responsibility for more than 830 victims worldwide since its emergence in August 2023. Security researchers attribute its growth to a combination of aggressive affiliate recruitment, opportunistic targeting, and the disruption of major ransomware groups such as ALPHV/BlackCat and LockBit, which created opportunities for newer actors to expand their influence within the cybercrime ecosystem.

Jun 19, 2026

Open AI Assisted CTF: Same Systems. Two Scans. Before and After Saner
AI attack surface reduction using Saner

CVE Research

AI Assisted CTF: Same Systems. Two Scans. Before and After Saner

What changed when AI tested the lab before and after Saner reduced the usable attack surface

Jun 12, 2026