Cleartext Transmission of Sensitive Information The advisory has been revoked - it doesn't affect any version of package python-asyncssh  (opens in a new tab)


Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN10-PYTHONASYNCSSH-6130548
  • published19 Dec 2023
  • disclosed20 Jan 2024

Introduced: 19 Dec 2023

CVE-2023-46447  (opens in a new tab)
CWE-319  (opens in a new tab)

Amendment

The Debian security team deemed this advisory irrelevant for Debian:10.

NVD Description

Note: Versions mentioned in the description apply only to the upstream python-asyncssh package and not the python-asyncssh package as distributed by Debian.

The POPS! Rebel application 5.0 for Android, in POPS! Rebel Bluetooth Glucose Monitoring System, sends unencrypted glucose measurements over BLE.