CVE-2023-5616
published 2025-04-15CVE-2023-5616: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for…
PriorityP423medium4.9CVSS 3.1
AVLACHPRNUINSUCLILAL
EPSS
0.22%
12.8th percentile
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical_ltd | ubuntu_s_gnome-control-center | >= 1:3 < 1:3.36.5-0ubuntu4.1 | 1:3.36.5-0ubuntu4.1 |
| canonical_ltd | ubuntu_s_gnome-control-center | >= 1:41 < 1:41.7-0ubuntu0.22.04.8 | 1:41.7-0ubuntu0.22.04.8 |
| canonical_ltd | ubuntu_s_gnome-control-center | >= 1:44 < 1:44.0-1ubuntu6.1 | 1:44.0-1ubuntu6.1 |
| canonical_ltd | ubuntu_s_gnome-control-center | >= 1:45 < 1:45.0-1ubuntu3.1 | 1:45.0-1ubuntu3.1 |
| debian | gnome-control-center | — | — |
| gnome | control_center | >= 1.3 < 1.3.36.5-0ubuntu4.1 | 1.3.36.5-0ubuntu4.1 |
| gnome | control_center | >= 1.41 < 1.41.7-0ubuntu0.22.04.8 | 1.41.7-0ubuntu0.22.04.8 |
| gnome | control_center | >= 1.44 < 1.44.0-1ubuntu6.1 | 1.44.0-1ubuntu6.1 |
| gnome | control_center | >= 1.45 < 1.45.0-1ubuntu3.1 | 1.45.0-1ubuntu3.1 |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-5616: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for o
osv·2025-04-15·CVSS 4.9
CVE-2023-5616 [MEDIUM] CVE-2023-5616: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for o
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
GHSA
GHSA-78gq-q74g-w632: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for o
ghsa_unreviewed·2025-04-15
CVE-2023-5616 [MEDIUM] CWE-290 GHSA-78gq-q74g-w632: In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for o
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Red Hat
gnome-control-center: Remote login misconfiguration in GNOME Control Center
vendor_redhat·2025-04-15·CVSS 4.9
CVE-2023-5616 [MEDIUM] CWE-290 gnome-control-center: Remote login misconfiguration in GNOME Control Center
gnome-control-center: Remote login misconfiguration in GNOME Control Center
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
A flaw was found in the GNOME Control Center. This vulnerability allows the SSH service to be improperly enabled without properly managing systemd units, which could unintentionally expose remote login access through insecure service activation management.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment,
Ubuntu
GNOME Settings vulnerability
vendor_ubuntu·2023-12-13
CVE-2023-5616 GNOME Settings vulnerability
Title: GNOME Settings vulnerability
Summary: GNOME Settings could allow unintended access to network services.
Zygmunt Krynicki discovered that GNOME Settings did not accurately reflect
the SSH remote login status when the system was configured to use systemd
socket activation for OpenSSH. Remote SSH access may be unknowingly
enabled, contrary to expectation.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2023-5616: gnome-control-center - In Ubuntu, gnome-control-center did not properly reflect SSH remote login status...
vendor_debian·2023·CVSS 4.9
CVE-2023-5616 [MEDIUM] CVE-2023-5616: gnome-control-center - In Ubuntu, gnome-control-center did not properly reflect SSH remote login status...
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-15
Published