Vulnerability Details CVE-2023-51384
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 13.5%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2023-51384
-
cpe:2.3:a:openbsd:openssh:8.9
-
cpe:2.3:a:openbsd:openssh:9.0
-
cpe:2.3:a:openbsd:openssh:9.1
-
cpe:2.3:a:openbsd:openssh:9.2
-
cpe:2.3:a:openbsd:openssh:9.3
-
cpe:2.3:a:openbsd:openssh:9.4
-
cpe:2.3:a:openbsd:openssh:9.5
-
cpe:2.3:o:debian:debian_linux:11.0
-
cpe:2.3:o:debian:debian_linux:12.0