CVE-2021-36368 | OpenSSH up to 8.8 FIDO Authentication improper authentication
A vulnerability was found in OpenSSH up to 8.8. It has been rated as critical. Affected is an unknown function of the component FIDO Authentication. The manipulation leads to improper authentication.
This vulnerability is documented as CVE-2021-36368. The attack can be initiated remotely. There is not any exploit available.
It is still unclear if this vulnerability genuinely exists.
Upgrading the affected component is advised.
the vendor's position is "this is not an authentication bypass, since nothing is being bypassed."