Exploit for #VU78454 Untrusted search path in OpenSSH


Published: 2024-03-22 | Updated: 2024-04-05

Vulnerability identifier: #VU78454

Vulnerability risk: Medium

CVSSv3.1: 6.7 [CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2023-38408

CWE-ID: CWE-426

Exploitation vector: Network

Exploits in database: 2

Impact: Code execution

Vulnerable software:
OpenSSH
Server applications / Remote management servers, RDP, SSH

Vendor: OpenSSH