QID 38904
Date Published: 2023-07-19
QID 38904: OpenSSH Remote Code Execution (RCE) Vulnerability in its forwarded ssh-agent
OpenSSH (OpenBSD Secure Shell) is a set of computer programs providing encrypted communication sessions over a computer network using the SSH protocol.
OpenSSH contains the following vulnerabilities:
We have discovered this vulnerability (CVE-2023-38408) - It is a condition where specific libraries loaded via ssh-agent(1)'s PKCS#11 support could be abused to achieve remote code execution via a forwarded agent socket if the conditions mentioned here are met.
Affected Versions:
OpenSSH versions prior to 9.3p2
QID Detection Logic:
This unauthenticated detection works by reviewing the version of the OpenSSH service.
Successful exploitation allows an attacker to perform a remote code execution vulnerability via a forwarded agent socket.
Solution
Customers are advised to upgrade to OpenSSH 9.3p2 or later to remediate these vulnerabilities.
Vendor References
- OpenSSH 9.3p2 -
www.openssh.com/txt/release-9.3p2
CVEs related to QID 38904
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| OpenSSH 9.3p2 |
|