CVE-2016-10009 describes an untrusted search path vulnerability in ssh-agent.c within OpenSSH versions prior to 7.4. This flaw allows remote attackers to execute arbitrary local PKCS#11 modules by manipulating a forwarded agent-socket. Rated as High severity (CVSS 7.3), the vulnerability has a low attack complexity and could lead to partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation (KEV: No), exploit code for arbitrary library loading is publicly available via ExploitDB, and the vulnerability has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.