CWE-322: Key Exchange without Entity Authentication
The product performs a key exchange with an actor without verifying the identity of that actor.
25 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-20163 — Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
- CVE-2024-47519 — Backup uploads to ETM subject to man-in-the-middle interception
- CVE-2026-1709 — Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
- CVE-2026-33697 — CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
- CVE-2025-62501 — SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53
- CVE-2025-54422 — Sandboxie exposes encrypted sandbox key during password change
- CVE-2026-58065 — Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
- CVE-2024-4871 — Foreman: host ssh key not being checked in remote execution
- CVE-2026-45361 — Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
- CVE-2026-44467 — Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
- CVE-2025-13914 — Apstra: SSH host key validation vulnerability for managed devices
- CVE-2026-18654 — Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
- CVE-2026-1354 — Zero Motorcycles Firmware Key Exchange without Entity Authentication
Recently published
- CVE-2026-18654 — Disabled SSH host key verification in Amazon AWS CLI EMR helper commands
- CVE-2026-58065 — Apache Airflow Git provider: Git provider hook defaults to StrictHostKeyChecking=no, disabling SSH host-key verification
- CVE-2026-45361 — Apache Airflow Google provider: SSH host key verification disabled in ComputeEngineSSHHook (paramiko AutoAddPolicy default)
- CVE-2026-44467 — Claude Desktop: SSH Host Key Verification Bypass Allows Man-in-the-Middle Attack on Remote Sessions
- CVE-2026-1354 — Zero Motorcycles Firmware Key Exchange without Entity Authentication
- CVE-2025-13914 — Apstra: SSH host key validation vulnerability for managed devices
- CVE-2026-33697 — CoCoS attested TLS is vulnerable to relay attacks via extracted ephemeral TLS keys
- CVE-2026-1709 — Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication
- CVE-2025-62501 — SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53
- CVE-2025-54422 — Sandboxie exposes encrypted sandbox key during password change
- CVE-2025-20163 — Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
- CVE-2024-47519 — Backup uploads to ETM subject to man-in-the-middle interception
- CVE-2024-4871 — Foreman: host ssh key not being checked in remote execution