Logo
vulnerabilityCVE-2021-36369
Name
CVE-2021-36369
Source
NVD ( link)Debian ( link)
Description
An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass. Thus, it allows an attacker to abuse a forwarded agent for logging on to another server unnoticed.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
dropbear
Patched

Vulnerability Ratings#


7.5
CVSSv31
7.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2026.91
Not Affected
buildroot
master
2026.91
Not Affected
openwrt
master
2026.91-r1
Not Affected
openwrt
openwrt-25.12
2025.89-r1
Not Affected
yocto
master
2026.91
Not Affected
yocto
scarthgap
2022.83
Not Affected

Resolved with patches#


dropbear (yocto:kirkstone)

#
Title
Author
Resolve
1
added option to disable trivial auth methods (#128)
Manfred Kaiser <37737811+manfred-kaiser@users.noreply.github.com>
CVE-2021-36369