CVE-2021-41617
published 2021-09-26CVE-2021-41617: sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not…
PriorityP337high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
2.54%
83.3th percentile
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Affected
20 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | openssh | < openssh 1:8.7p1-1 (bookworm) | openssh 1:8.7p1-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cm1_openssh_8.8p1-1_on_cbl_mariner_1.0 | — | — |
| openbsd | openssh | >= 0 < 1:8.4p1-5+deb11u3 | 1:8.4p1-5+deb11u3 |
| openbsd | openssh | >= 0 < 1:8.7p1-1 | 1:8.7p1-1 |
| openbsd | openssh | >= 0 < 1:8.7p1-1 | 1:8.7p1-1 |
| openbsd | openssh | >= 0 < 1:8.7p1-1 | 1:8.7p1-1 |
| openbsd | openssh | >= 0 < 1:8.2p1-4ubuntu0.11 | 1:8.2p1-4ubuntu0.11 |
| openbsd | openssh | >= 0 < 1:8.9p1-3ubuntu0.6 | 1:8.9p1-3ubuntu0.6 |
| openbsd | openssh | >= 6.2 < 8.8 | 8.8 |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
| paloalto | prisma_sd | — | — |
| paloalto | prisma_sd-wan_ion | — | — |
| starwindsoftware | starwind_virtual_san | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv7.0HIGH
vendor_debian7.0HIGH
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU Family
cisa_ics·2025-06-12
Siemens SIMATIC S7-1500 CPU Family
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU Family
Release DateJune 12, 2025
Alert CodeICSA-25-162-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.7
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU family
- Vulnerabilities: Missing Encryption of Sensitive Data, Out-of-bounds Read, Use After Free, Stack-
Palo Alto
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
vendor_paloalto·2024-04-05·CVSS 4.3
CVE-2007-2768 [MEDIUM] PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Prisma SD-WAN ION. While Prisma SD-WAN ION may include the
CVEs: CVE-2007-2768, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-20012, CVE-2016-8858, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2021-41617, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-28531, CVE-2023-38408, CVE-2023-51384, CVE-2023-51385, CVE-2023-51767
Affected products: Prisma SD
Ubuntu
OpenSSH vulnerabilities
vendor_ubuntu·2024-01-03·CVSS 7.0
CVE-2021-41617 [HIGH] OpenSSH vulnerabilities
Title: OpenSSH vulnerabilities
Summary: Several security issues were fixed in OpenSSH.
It was discovered that OpenSSH incorrectly handled supplemental groups when
running helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand as a different user. An attacker could possibly
use this issue to escalate privileges. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-41617)
It was discovered that OpenSSH incorrectly added destination constraints
when PKCS#11 token keys were added to ssh-agent, contrary to expectations.
This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-51384)
It was discovered that OpenSSH incorrectly handled user names or host names
with shell metacharacters. An attacker could possibly use this issue to
perform OS command injection.
Ubuntu
OpenSSH vulnerability
vendor_ubuntu·2022-10-10
CVE-2021-41617 OpenSSH vulnerability
Title: OpenSSH vulnerability
Summary: OpenSSH could be made to run arbitrary code if it some
non-default configuration are in use.
It was discovered that OpenSSH incorrectly handled certain helper programs.
An attacker could possibly use this issue to arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Palo Alto
Informational: Impact of the OpenSSH Vulnerability CVE-2021-41617 on PAN-OS
vendor_paloalto·2021-11-30·CVSS 7.0
CVE-2021-41617 [HIGH] CWE-250 Informational: Impact of the OpenSSH Vulnerability CVE-2021-41617 on PAN-OS
Informational: Impact of the OpenSSH Vulnerability CVE-2021-41617 on PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the OpenSSH software CVE-2021-41617 vulnerability.
PAN-OS and Prisma SD-WAN ION software does not utilize the ssh configuration options required to exploit this vulnerability. There are no scenarios that enable successful exploitation of the vulnerability in the listed software. As a result, there is no known security impact for this vulnerability.
Affected products: PAN-OS, Prisma SD-WAN ION
Solution: No product updates are required for this vulnerability.
Red Hat
openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured
vendor_redhat·2021-09-26·CVSS 7.0
CVE-2021-41617 [HIGH] CWE-273 openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured
openssh: privilege escalation when AuthorizedKeysCommand or AuthorizedPrincipalsCommand are configured
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
A flaw was found in OpenSSH. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user. Depending on system configuration
Microsoft
sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for
vendor_msrc·2021-09-14·CVSS 7.0
CVE-2021-41617 [HIGH] sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for
sshd in OpenSSH 6.2 through 8.x before 8.8 when certain non-default configurations are used allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process if the configuration specifies running the command as a different user.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is c
Debian
CVE-2021-41617: openssh - sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurati...
vendor_debian·2021·CVSS 7.0
CVE-2021-41617 [HIGH] CVE-2021-41617: openssh - sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurati...
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
Scope: local
bookworm: resolved (fixed in 1:8.7p1-1)
bullseye: resolved (fixed in 1:8.4p1-5+deb11u3)
forky: resolved (fixed in 1:8.7p1-1)
sid: resolved (fixed in 1:8.7p1-1)
trixie: resolved (fixed in 1:8.7p1-1)
VulDB
OpenSSH up to 8.7 Supplemental Group privileges management (Nessus ID 214473)
vuldb·2026-07-14·CVSS 7.0
CVE-2021-41617 [HIGH] OpenSSH up to 8.7 Supplemental Group privileges management (Nessus ID 214473)
A vulnerability, which was classified as critical, has been found in OpenSSH up to 8.7. Affected by this vulnerability is an unknown functionality of the component Supplemental Group Handler. The manipulation leads to improper privilege management.
This vulnerability is traded as CVE-2021-41617. Access to the local network is required for this attack to succeed. There is no exploit available.
It is advisable to upgrade the affected component.
OSV
openssh vulnerabilities
osv·2024-01-03·CVSS 7.0
CVE-2021-41617 [HIGH] openssh vulnerabilities
openssh vulnerabilities
It was discovered that OpenSSH incorrectly handled supplemental groups when
running helper programs for AuthorizedKeysCommand and
AuthorizedPrincipalsCommand as a different user. An attacker could possibly
use this issue to escalate privileges. This issue only affected Ubuntu
20.04 LTS. (CVE-2021-41617)
It was discovered that OpenSSH incorrectly added destination constraints
when PKCS#11 token keys were added to ssh-agent, contrary to expectations.
This issue only affected Ubuntu 22.04 LTS, and Ubuntu 23.04.
(CVE-2023-51384)
It was discovered that OpenSSH incorrectly handled user names or host names
with shell metacharacters. An attacker could possibly use this issue to
perform OS command injection. (CVE-2023-51385)
GHSA
GHSA-mxh4-p4w6-g844: sshd in OpenSSH 6
ghsa_unreviewed·2022-05-24
CVE-2021-41617 [HIGH] CWE-269 GHSA-mxh4-p4w6-g844: sshd in OpenSSH 6
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
OSV
CVE-2021-41617: sshd in OpenSSH 6
osv·2021-09-26·CVSS 7.0
CVE-2021-41617 [HIGH] CVE-2021-41617: sshd in OpenSSH 6
sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration specifies running the command as a different user.
No detection rules found.
No public exploits indexed.
https://bugzilla.suse.com/show_bug.cgi?id=1190975https://lists.debian.org/debian-lts-announce/2023/12/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/https://security.netapp.com/advisory/ntap-20211014-0004/https://www.debian.org/security/2023/dsa-5586https://www.openssh.com/security.htmlhttps://www.openssh.com/txt/release-8.8https://www.openwall.com/lists/oss-security/2021/09/26/1https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.starwindsoftware.com/security/sw-20220805-0001/https://www.tenable.com/plugins/nessus/154174https://bugzilla.suse.com/show_bug.cgi?id=1190975https://lists.debian.org/debian-lts-announce/2023/12/msg00017.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6XJIONMHMKZDTMH6BQR5TNLF2WDCGWED/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KVI7RWM2JLNMWTOFK6BDUSGNOIPZYPUT/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/W44V2PFQH5YLRN6ZJTVRKAD7CU6CYYET/https://security.netapp.com/advisory/ntap-20211014-0004/https://www.debian.org/security/2023/dsa-5586https://www.openssh.com/security.htmlhttps://www.openssh.com/txt/release-8.8https://www.openwall.com/lists/oss-security/2021/09/26/1https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.starwindsoftware.com/security/sw-20220805-0001/https://www.tenable.com/plugins/nessus/154174https://cert-portal.siemens.com/productcert/html/ssa-019113.htmlhttps://cert-portal.siemens.com/productcert/html/ssa-082556.html
2021-09-26
Published