CVE-2023-51767
published 2023-12-24CVE-2023-51767: OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated…
PriorityP337high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.66%
47.5th percentile
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | fedora | — | — |
| openbsd | openssh | >= 0 < 9.7_p1-r0 | 9.7_p1-r0 |
| openbsd | openssh | >= 0 < 9.7_p1-r0 | 9.7_p1-r0 |
| openbsd | openssh | >= 0 < 9.7_p1-r0 | 9.7_p1-r0 |
| openbsd | openssh | >= 0 < 9.7_p1-r0 | 9.7_p1-r0 |
| openbsd | openssh | >= 0 < 9.7_p1-r0 | 9.7_p1-r0 |
| paloalto | pan-os | — | — |
| paloalto | prisma_sd | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
osv7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2010-1622 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Palo Alto
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
vendor_paloalto·2024-04-05·CVSS 4.3
CVE-2007-2768 [MEDIUM] PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
PAN-SA-2024-0003 Informational Bulletin: Impact of OSS CVEs in Prisma SD-WAN ION
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to Prisma SD-WAN ION. While Prisma SD-WAN ION may include the
CVEs: CVE-2007-2768, CVE-2016-10010, CVE-2016-10011, CVE-2016-10012, CVE-2016-20012, CVE-2016-8858, CVE-2019-6109, CVE-2019-6110, CVE-2019-6111, CVE-2020-12062, CVE-2021-41617, CVE-2022-4450, CVE-2023-0215, CVE-2023-0286, CVE-2023-28531, CVE-2023-38408, CVE-2023-51384, CVE-2023-51385, CVE-2023-51767
Affected products: Prisma SD
Red Hat
openssh: authentication bypass via row hammer attack
vendor_redhat·2023-12-24·CVSS 7.0
CVE-2023-51767 [HIGH] CWE-287 openssh: authentication bypass via row hammer attack
openssh: authentication bypass via row hammer attack
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
An authentication bypass vulnerability was found in a modified version of OpenSSH. When common types of DRAM memory are used, it might allow row hammer attacks because the integer value of authenticated authpassword does not res
OSV
CVE-2023-51767: OpenSSH through 9
osv·2023-12-24·CVSS 7.0
CVE-2023-51767 [HIGH] CVE-2023-51767: OpenSSH through 9
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
OSV
CVE-2023-51767: OpenSSH through 10
osv·2023-12-24·CVSS 7.0
CVE-2023-51767 [HIGH] CVE-2023-51767: OpenSSH through 10
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
GHSA
GHSA-27q9-h529-q4g3: OpenSSH through 9
ghsa_unreviewed·2023-12-24
CVE-2023-51767 [HIGH] GHSA-27q9-h529-q4g3: OpenSSH through 9
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/security/cve/CVE-2023-51767https://arxiv.org/abs/2309.02545https://bugzilla.redhat.com/show_bug.cgi?id=2255850https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878https://security.netapp.com/advisory/ntap-20240125-0006/https://ubuntu.com/security/CVE-2023-51767https://www.openwall.com/lists/oss-security/2025/09/22/1http://www.openwall.com/lists/oss-security/2025/09/22/1http://www.openwall.com/lists/oss-security/2025/09/22/2http://www.openwall.com/lists/oss-security/2025/09/23/1http://www.openwall.com/lists/oss-security/2025/09/23/3http://www.openwall.com/lists/oss-security/2025/09/23/4http://www.openwall.com/lists/oss-security/2025/09/23/5http://www.openwall.com/lists/oss-security/2025/09/24/4http://www.openwall.com/lists/oss-security/2025/09/24/7http://www.openwall.com/lists/oss-security/2025/09/25/2http://www.openwall.com/lists/oss-security/2025/09/25/6http://www.openwall.com/lists/oss-security/2025/09/26/2http://www.openwall.com/lists/oss-security/2025/09/26/4http://www.openwall.com/lists/oss-security/2025/09/27/1http://www.openwall.com/lists/oss-security/2025/09/27/2http://www.openwall.com/lists/oss-security/2025/09/27/3http://www.openwall.com/lists/oss-security/2025/09/27/4http://www.openwall.com/lists/oss-security/2025/09/27/5http://www.openwall.com/lists/oss-security/2025/09/27/6http://www.openwall.com/lists/oss-security/2025/09/27/7http://www.openwall.com/lists/oss-security/2025/09/28/7http://www.openwall.com/lists/oss-security/2025/09/29/1http://www.openwall.com/lists/oss-security/2025/09/29/4http://www.openwall.com/lists/oss-security/2025/09/29/5http://www.openwall.com/lists/oss-security/2025/09/29/6http://www.openwall.com/lists/oss-security/2025/10/01/1http://www.openwall.com/lists/oss-security/2025/10/01/2https://access.redhat.com/security/cve/CVE-2023-51767https://arxiv.org/abs/2309.02545https://bugzilla.redhat.com/show_bug.cgi?id=2255850https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878https://security.netapp.com/advisory/ntap-20240125-0006/https://ubuntu.com/security/CVE-2023-51767
2023-12-24
Published