Inadequate Encryption Strength in OpenSSH - CVE-2023-51384
Published: December 27, 2023
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to an error in the ssh-agent, which causes certain destination constraints to be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Affected software
IBM Security Verify Access
Debian Linux
IBM AIX
macOS
Ubuntu
UCC Edge
Verify Identity Access Digital Credentials
Storage Protect Plus Container Agent
IBM VIOS
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh (Debian package)
How to mitigate CVE-2023-51384
UCC Edge - update to 2.3.1
macOS - update to 14.4 23E214
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh-server (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
Storage Protect Plus Container Agent - update to 10.1.12.7
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenSSH
- Debian update for openssh
- Ubuntu update for openssh
- Multiple vulnerabilities in IBM VIOS and IBM AIX
- Multiple vulnerabilities in Apple macOS Sonoma
- Multiple vulnerabilities in IBM Storage Protect Plus Container Agent
- Multiple vulnerabilities in Dell UCC Edge
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access