CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.5. It may be remotely exploitable.
CVE
CVE-2014-2653
Severity
MEDIUM
CVSS
6.5
EPSS
1.99%
Original NVD Description
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.