CVE-2023-38408
CRITICAL 9.8EPSS 79.7%
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 79.70% chance of exploitation in the next 30 days, 100th percentile
- Published
- 2023-07-20
- Updated
- 2024-10-15
Proof-of-concept exploits (10)
- http://packetstormsecurity.com/files/173661/OpenSSH-Forwarded-SSH-Agent-Remote-Code-Execu…
- Adel2411/cve-2023-384085★ · 2025-07-16
- LucasPDiniz/CVE-2023-3840845★ · 2024-06-30
- TX-One/CVE-2023-384087★ · 2025-04-19
- a-s-m-asadujjaman/exploitables0★ · 2026-06-12
- classic130/CVE-2023-384083★ · 2023-07-25
- kali-mx/CVE-2023-3840853★ · 2024-11-09
- mrtacojr/CVE-2023-384081★ · 2024-07-17
- snowcra5h/CVE-2023-384088★ · 2023-07-25
- wxrdnx/CVE-2023-384080★ · 2024-12-20