This security advisory addresses a vulnerability identified in ethernet switches.
CVE-2023-38408
Because of an unreliable search path, the PKCS#11 feature in OpenSSH’s ssh-agent before 9.3p2 allows remote code execution if an agent is sent to a system controlled by an attacker. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: This issue exists because of an incomplete fix for CVE-2016-10009. (Source: cve.org)
Since this issue is considered high severity, users should immediately apply the solutions to mitigate associated security risks.
The Identified Vulnerability Type and Potential Impact
| CVE ID |
Vulnerability Type |
Impact |
| CVE-2023-38408 |
CWE-428: Unquoted Search Path or Element
|
Remote code execution if an agent is forwarded to an attacker-controlled system. |
Vulnerability Scoring Details
|
CVE ID
|
Base Score
|
Vector
|
Severity |
Unauthenticated
Remote Exploits
|
| CVE-2023-38408 |
CVSS 3.1: 9.8
|
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
Critical |
Yes |