QID 38896

Date Published: 2023-05-22

QID 38896: OpenSSH Sensitive Information Disclosure Vulnerability

OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.

Affected Versions:
OpenSSH version 8.9 and above prior to 9.3

QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.

Successfully exploitation of this vulnerability could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade to OpenSSH 9.3 or later to remediate these vulnerabilities.
    Vendor References

    CVEs related to QID 38896

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-28531 URL Logo www.openssh.com/txt/release-9.3