OS Command Injection in OpenSSH - CVE-2023-51385

 

OS Command Injection in OpenSSH - CVE-2023-51385

Published: December 26, 2023 / Updated: November 8, 2024


Vulnerability identifier: #VU84789
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-51385
CWE-ID: CWE-78
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.

The vulnerability exists due to improper input validation when processing user names, if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. A remote attacker can execute arbitrary OS commands via an untrusted Git repository.


Affected software

OpenSSH
BIG-IQ Centralized Management
IBM Security Verify Access
Juniper Junos Space
Gentoo Linux
Debian Linux
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Software Development Kit 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Desktop 15
F5OS
SUSE Manager Server
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
IBM i
IBM AIX
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
macOS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
SUSE Linux Enterprise Desktop 15 SP4 LTSS
SUSE Linux Enterprise Server 15 SP4 LTSS
Basesystem Module
Desktop Applications Module
openSUSE Leap
Ubuntu
openEuler
Oracle Solaris
Red Hat OpenShift Builds
OpenShift Logging
Red Hat Migration Toolkit for Applications
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Security Verify Governance
Migration Toolkit for Containers
Red Hat OpenShift Container Platform
Traffix SDC
UCC Edge
Verify Identity Access Digital Credentials
Storage Copy Data Management
PowerStore X
EMC ECS
PowerStore T
Enterprise SONiC
Storage Resource Manager
Dell Policy Manager for Secure Connect Gateway (SCG)
Total Storage Service Console (TSSC) / TS4500 IMC
Storage Protect Plus Container Agent
Storage Protect Plus Server
EMC Cloud Tiering Appliance
IBM VIOS
Juniper Secure Analytics (JSA)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
openssh-server (Ubuntu package)
openssh-client (Ubuntu package)
pam_ssh_agent_auth
openssh-testuser
openssh-debugsource
openssh-fips
openssh-debuginfo
openssh-askpass-gnome-debuginfo
openssh
openssh-helpers
openssh-helpers-debuginfo
openssh-askpass-gnome
openssh (Red Hat package)
openssh-askpass
openssh-cavs
openssh-clients
openssh-keycat
openssh-ldap
openssh-server
openssh-askpass-gnome-debugsource
openssh-help
openssh (Debian package)
openssh-common-debuginfo
openssh-clients-debuginfo
openssh-server-debuginfo
openssh-common
openssh-cavs-debuginfo
openssh-doc
openssh-sk-dummy
openssh-server-config-disallow-rootlogin
IBM Security Guardium
BIG-IP
BIG-IP Next Central Manager
RSA Authentication Manager
Red Hat OpenShift GitOps
IBM Integrated Analytics System
Dell EMC Storage Monitoring and Reporting (SMR)
OpenShift Data Foundation (formerly OpenShift Container Storage)
RecoverPoint for VMs
IBM Qradar SIEM
AirWave Management Platform

How to mitigate CVE-2023-51385

Install updates from vendor's website.

OpenSSH - update to 9.6p1
Red Hat OpenShift Builds - update to 1.0.1
Migration Toolkit for Containers - addressed in versions 1.7.15, 1.8.3
UCC Edge - update to 2.3.1
Red Hat OpenShift Container Platform - addressed in versions 4.12.53, 4.14.17, 4.15.3
Red Hat Migration Toolkit for Applications - update to 7.0.2
Juniper Secure Analytics (JSA) - update to 7.5.0 UP8 IF03
macOS - update to 14.4 23E214
openssh-server (Ubuntu package) - addressed in versions Ubuntu Pro (Infra-only), 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh-client (Ubuntu package) - addressed in versions Ubuntu Pro, 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
pam_ssh_agent_auth - addressed in versions 0.10.3-7.20.0.1, 0.10.3-7.20.0.4
pam_ssh_agent_auth - addressed in versions 0.10.3-9.28, 0.10.4-4.23, 0.10.4-4.25
openssh-testuser - update to 0-81.12.1
Red Hat OpenShift GitOps - update to 1.11
Storage Copy Data Management - update to 2.2.23.1
PowerStore X - update to 3.2.1.4-2386214
EMC ECS - update to 3.8.1.1
PowerStore T - update to 4.0.0.2-2365061
Enterprise SONiC - update to 4.2.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.8.5
Storage Resource Manager - update to 4.10.0.3
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.10.0.3
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.15.0
Dell Policy Manager for Secure Connect Gateway (SCG) - update to 5.24.00.14
Dell Secure Connect Gateway - update to 5.24.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
openssh-debugsource - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-fips - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-askpass-gnome-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-helpers - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-helpers-debuginfo - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-askpass-gnome - addressed in versions 7.2p2-81.12.1, 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 8 IF01
openssh (Red Hat package) - addressed in versions 8.0p1-7.el8_4.2, 8.0p1-19.el8_9.2, 8.7p1-13.el9_0.1, 8.7p1-34.el9_3.3
openssh - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-askpass - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-cavs - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4
openssh-clients - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-keycat - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-ldap - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4
openssh-server - addressed in versions 8.0p1-20.0.1, 8.0p1-20.0.4, 9.3p2-6
openssh-askpass-gnome-debugsource - addressed in versions 8.1p1-150200.5.46.1, 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh - update to 8.2p1-28
openssh-help - update to 8.2p1-28
openssh-keycat - update to 8.2p1-28
openssh-debugsource - update to 8.2p1-28
openssh-askpass - update to 8.2p1-28
openssh-debuginfo - update to 8.2p1-28
openssh-clients - update to 8.2p1-28
openssh-ldap - update to 8.2p1-28
openssh-server - update to 8.2p1-28
openssh-cavs - update to 8.2p1-28
AirWave Management Platform - update to 8.3.0.3
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
openssh-server - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-common-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-clients-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-server-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-cavs - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-common - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-cavs-debuginfo - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
openssh-clients - addressed in versions 8.4p1-150300.3.30.1, 9.6p1-150600.6.6.1
RSA Authentication Manager - update to 8.7 SP2 Patch 2
IBM Integrated Analytics System - update to 8.8.24.10.SP1
openssh-doc - update to 9.3p2-6
openssh-sk-dummy - update to 9.3p2-6
Total Storage Service Console (TSSC) / TS4500 IMC - addressed in versions 9.4.26, 9.5.8
openssh-server-config-disallow-rootlogin - update to 9.6p1-150600.6.6.1
IBM Security Verify Governance - update to 10.0.2.0.4
Storage Protect Plus Container Agent - update to 10.1.12.7
Storage Protect Plus Server - update to 10.1.16.1
Oracle Solaris - addressed in versions 11.3 ESU 36.35, 11.4 SRU 89
EMC Cloud Tiering Appliance - update to 13.2.0.2.29
Juniper Junos Space - update to 24.1R1 Patch V2

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins