CVE-2023-28531Openssh vulnerability

11 documents10 sources
Severity
9.8CRITICALNVD
EPSS
0.4%
top 40.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 17
Latest updateDec 19

Description

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDopenbsd/openssh8.99.3
Debianopenbsd/openssh< 1:9.2p1-2+deb12u2+2

🔴Vulnerability Details

4
OSV
openssh vulnerabilities2023-12-19
CVEList
CVE-2023-28531: ssh-add in OpenSSH before 92023-03-17
GHSA
GHSA-j839-ff8c-f62x: ssh-add in OpenSSH before 92023-03-17
OSV
CVE-2023-28531: ssh-add in OpenSSH before 92023-03-17

📋Vendor Advisories

5
Ubuntu
OpenSSH vulnerabilities2023-12-19
BSD
FreeBSD-SA-23:05.openssh: ssh-add does not honor per-hop destination constraints2023-06-21
Red Hat
openssh: smartcard keys to ssh-agent without the intended per-hop destination constraints.2023-03-17
Microsoft
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.2023-03-14
Debian
CVE-2023-28531: openssh - ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the inten...2023

🕵️Threat Intelligence

1
Huntress
CVE-2023-28531 (OpenSSH Constraint Bypass) Vulnerability: Analysis, Impact, Mitigation | Huntress
CVE-2023-28531 — Openbsd Openssh vulnerability | cvebase