CVE-2023-51384 describes an incomplete application of destination constraints in ssh-agent within OpenSSH versions prior to 9.6, specifically affecting PKCS#11-hosted private keys where constraints are only applied to the first key if a token returns multiple. This vulnerability has a CVSS score of 5.5 (MEDIUM), indicating a local attack vector with low complexity, potentially leading to high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE. Affected products include Debian Linux and OpenBSD OpenSSH.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.9, < 9.6CPE matchmatch criteria | cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024HP ThinPro 8.0 SP 9 Security Updates
Jun 17, 2024CVE-2023-51384
Jun 11, 2024openssh: destination constraints only apply to first PKCS#11 key
Dec 18, 2023In ssh-agent in OpenSSH before 9.6 certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys these constraints are only applied to the first key even if a PKCS#11 token returns multiple keys.
Dec 12, 2023