Skip to content
QuantumScanRelatório público de scan

Repositório

openssh/openssh-portable

Escaneado em 10 de jun. de 2026

78

Risk score/ 100

Risco alto

Resumo

OpenSSH Portable has critical post-quantum cryptography vulnerabilities with 111 quantum-vulnerable cryptographic implementations across 22 files. All primary key exchange (ECDH, X25519), signature algorithms (RSA, ECDSA, Ed25519), and legacy ciphers (3DES, MD5, SHA-1) are susceptible to quantum attacks via Shor's and Grover's algorithms. Immediate migration planning to NIST-approved PQC algorithms is required for regulatory compliance.

Crítico

30

Alto

111

Médio

15

Baixo

0

Principais findings

  • CríticoMD5

    openbsd-compat/md5.c:51

    SHA3-256 or SHA-256

    Evidência
    * Start MD5 accumulation.  Set bit count to 0 and buffer to mysterious
  • Crítico3DES / TripleDES

    cipher.c:158

    Evidência
    if (strcmp("3des-cbc", c->name) == 0)
  • Crítico3DES / TripleDES

    cipher.c:88

    Evidência
    { "3des-cbc",		8, 24, 0, 0, CFLAG_CBC, EVP_des_ede3_cbc },
  • CríticoMD5

    openbsd-compat/md5.h:4

    SHA3-256 or SHA-256

    Evidência
    * This code implements the MD5 message-digest algorithm.
  • CríticoMD5

    openbsd-compat/md5.h:1

    SHA3-256 or SHA-256

    Evidência
    /*	$OpenBSD: md5.h,v 1.17 2012/12/05 23:19:57 deraadt Exp $	*/

+ 151 findings no relatório completo

Escaneie seu próprio repositório

Grátis. Resultados em ~90 segundos. CBOM + PDF DORA/NIS2 inclusos.

Começar scan grátis