CVE-2023-38408
Aliases:ALPINE-CVE-2023-38408DEBIAN-CVE-2023-38408CGA-jvq7-32rc-8m88CGA-vc8q-mv6j-3696
Advisory lineage Upstream: 0 Downstream: 22
Modified
Published: 20 Jul 2023, 00:00
Last modified:15 Oct 2024, 18:33
Vulnerability Summary
Overall Risk (default)
high
70/100 CVSS Score
9.8 CRITICAL
v3.1 (cve.org)
EPSS Score
79.7% CRITICAL
80% probability +12.39%
KEV
Not listed
Ransomware
No reports
Public exploits
3 found
Dark Web
Not detected
Timeline
20 Jul 2023, 00:00
Published
Vulnerability first disclosed
15 Oct 2024, 18:33
Last Modified
Vulnerability information updated
Description
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Trends
Current EPSS score: 79.70%• Percentile: 100%
Techniques & Countermeasures
- CWE-428•Unquoted Search Path or Element
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Affected Systems
- alpine•openssh
< 9.0_p1-r4 | < 9.1_p1-r4
- chainguard•openssh
< 9.3_p2-r0
- wolfi•openssh
< 9.3_p2-r0
- debian•openssh
< 1:8.4p1-5+deb11u2 | < 1:9.2p1-2+deb12u1 | < 1:9.3p2-1 | < 1:9.3p2-1
- fedoraproject•fedora
37 | 38
- openbsd•openssh
< 9.3 | 9.3 | 9.3:p1
References (24)
- https://news.ycombinator.com/item?id=36790196
- https://blog.qualys.com/vulnerabilities-threat-research/2023/07/19/cve-2023-38408-remote-code-execution-in-opensshs-forwarded-ssh-agent
- https://www.qualys.com/2023/07/19/cve-2023-38408/rce-openssh-forwarded-ssh-agent.txt
- https://github.com/openbsd/src/commit/f8f5a6b003981bb824329dc987d101977beda7ca
- https://github.com/openbsd/src/commit/7bc29a9d5cd697290aa056e94ecee6253d3425f8
- https://github.com/openbsd/src/commit/f03a4faa55c4ce0818324701dadbf91988d7351d
- https://www.openssh.com/txt/release-9.3p2
- https://www.openssh.com/security.html
- https://security.gentoo.org/glsa/202307-01
- http://www.openwall.com/lists/oss-security/2023/07/20/1
- http://www.openwall.com/lists/oss-security/2023/07/20/2
- http://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execution.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAXVQS6ZYTULFAK3TEJHRLKZALJS3AOU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CEBTJJINE2I3FHAUKKNQWMFGYMLSMWKQ/
- https://security.netapp.com/advisory/ntap-20230803-0010/
- https://lists.debian.org/debian-lts-announce/2023/08/msg00021.html
- http://www.openwall.com/lists/oss-security/2023/09/22/9
- http://www.openwall.com/lists/oss-security/2023/09/22/11
- https://support.apple.com/kb/HT213940
- https://www.vicarius.io/vsociety/posts/exploring-opensshs-agent-forwarding-rce-cve-2023-38408
- https://security.alpinelinux.org/vuln/CVE-2023-38408
- https://security-tracker.debian.org/tracker/CVE-2023-38408
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38408.json
- https://nvd.nist.gov/vuln/detail/CVE-2023-38408