THREAT OPS › Threat News › [NVD] CVE-2025-5372 (MEDIUM 5.0) — A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the fu
[NVD] CVE-2025-5372 (MEDIUM 5.0) — A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the fu
CVE-2025-5372 CVSS: 5.0 MEDIUM Published: 2025-07-04T06:15:24.930
A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function responsible for key derivation. Due to inconsistent interpretation of return values where OpenSSL uses 0 to indicate failure and libssh uses 0 for success—the function may mistakenly return a success status even wh
Indicators of compromise
- CVE-2025-5372cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-5372