QID 38868

Date Published: 2022-05-25

QID 38868: OpenSSH Privilege Escalation Vulnerability

OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.

Affected Versions:
OpenSSH 6.2 through 8.7

QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.

Attack may lead to privilege escalation due to supplemental groups not initialized.

  • CVSS V3 rated as High - 7 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Customers are advised to upgrade to OpenSSH 8.8 or later to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 38868

    Software Advisories
    Advisory ID Software Component Link
    CVE-2021-41617 URL Logo www.openssh.com/txt/release-8.8