CVE-2023-38408 is a critical remote code execution vulnerability in the PKCS#11 feature of ssh-agent in OpenSSH before version 9.3p2, stemming from an insufficiently trustworthy search path. This flaw primarily impacts Fedora and OpenBSD distributions. With a CVSS score of 9.8 (Critical), it allows an attacker to achieve full compromise (confidentiality, integrity, availability) if an agent is forwarded to an attacker-controlled system, requiring no user interaction. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media attention, indicating high awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 9.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
9.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:9.3:-:*:*:*:*:*:* | ||
9.3CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:9.3:p1:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* | ||
38CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches
Feb 26, 2026AS-2023-013: OpenSSH
Nov 29, 2023openssh: Remote code execution in ssh-agent PKCS#11 support
Jul 19, 2023ssh-agent(1) remote code execution relating to PKCS#11 providers.
Jul 19, 2023Remote code execution relating to PKCS#11 providers in ssh-agent(1)
Jul 19, 2023ssh-agent(1) remote code execution relating to PKCS#11 providers
Jul 19, 2023Remote code execution relating to PKCS#11 providers in ssh-agent(1).
Jul 19, 2023The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
Jul 11, 2023