Inadequate Encryption Strength in OpenSSH - CVE-2023-51384

 

Inadequate Encryption Strength in OpenSSH - CVE-2023-51384

Published: December 27, 2023


Vulnerability identifier: #VU84792
CSH Severity: Low
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-51384
CWE-ID: CWE-326
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error in the ssh-agent, which causes certain destination constraints to be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.


Affected software

OpenSSH
IBM Security Verify Access
Debian Linux
IBM AIX
macOS
Ubuntu
UCC Edge
Verify Identity Access Digital Credentials
Storage Protect Plus Container Agent
IBM VIOS
openssh-client (Ubuntu package)
openssh-server (Ubuntu package)
openssh (Debian package)

How to mitigate CVE-2023-51384

Install updates from vendor's website.

OpenSSH - update to 9.6p1
UCC Edge - update to 2.3.1
macOS - update to 14.4 23E214
openssh-client (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh-server (Ubuntu package) - addressed in versions 1:8.2p1-4ubuntu0.11, 1:8.9p1-3ubuntu0.6, 1:9.0p1-1ubuntu8.7, 1:9.3p1-1ubuntu3.2
openssh (Debian package) - addressed in versions 1:8.4p1-5+deb11u3, 1:9.2p1-2+deb12u2
Storage Protect Plus Container Agent - update to 10.1.12.7

External References

Related Security Bulletins