Lucene search

K
cve[email protected]CVE-2023-38408
HistoryJul 20, 2023 - 3:15 a.m.

CVE-2023-38408

2023-07-2003:15:10
CWE-428
web.nvd.nist.gov
2470
20
openssh
pkcs#11
ssh-agent
cve-2023-38408
remote code execution
nvd

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

Low

0.102 Low

EPSS

Percentile

95.0%

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

Affected configurations

NVD
Node
openbsdopensshRange<9.3
OR
openbsdopensshMatch9.3-
OR
openbsdopensshMatch9.3p1
Node
fedoraprojectfedoraMatch37
OR
fedoraprojectfedoraMatch38
CPENameOperatorVersion
openbsd:opensshopenbsd opensshlt9.3

References

Social References

More

9.8 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

8.3 High

AI Score

Confidence

Low

0.102 Low

EPSS

Percentile

95.0%