Repositorio
openssh/openssh-portable
Escaneado el 10 jun 2026
Puntuación de riesgo/ 100
Riesgo alto
Resumen
OpenSSH Portable has critical post-quantum cryptography vulnerabilities with 111 quantum-vulnerable cryptographic implementations across 22 files. All primary key exchange (ECDH, X25519), signature algorithms (RSA, ECDSA, Ed25519), and legacy ciphers (3DES, MD5, SHA-1) are susceptible to quantum attacks via Shor's and Grover's algorithms. Immediate migration planning to NIST-approved PQC algorithms is required for regulatory compliance.
30
111
15
0
Hallazgos principales
- CríticoMD5
openbsd-compat/md5.c:51
SHA3-256 or SHA-256
Evidencia
* Start MD5 accumulation. Set bit count to 0 and buffer to mysterious - Crítico3DES / TripleDES
cipher.c:158
Evidencia
if (strcmp("3des-cbc", c->name) == 0) - Crítico3DES / TripleDES
cipher.c:88
Evidencia
{ "3des-cbc", 8, 24, 0, 0, CFLAG_CBC, EVP_des_ede3_cbc }, - CríticoMD5
openbsd-compat/md5.h:4
SHA3-256 or SHA-256
Evidencia
* This code implements the MD5 message-digest algorithm. - CríticoMD5
openbsd-compat/md5.h:1
SHA3-256 or SHA-256
Evidencia
/* $OpenBSD: md5.h,v 1.17 2012/12/05 23:19:57 deraadt Exp $ */
+ 151 hallazgos más en el reporte completo
Escanea tu propio repositorio
Gratis. Resultados en ~90 segundos. CBOM + PDF DORA/NIS2 incluidos.