CVE-2024-47857

Critical severity, CVSS 9.8. EPSS: 0.5% chance of exploitation in the next 30 days.

SSH Communication Security PrivX versions between 18.0-36.0 implement insufficient validation on public key signatures when using native SSH connections via a proxy port. This allows an existing PrivX "account A" to impersonate another existing PrivX "account B" and gain access to SSH target hosts to which the "account B" has access.

Published 2025-01-31. Last modified 2026-06-17.