Improper Authentication in OpenSSH - CVE-2023-51767
Published: May 16, 2024
Vulnerability details
The vulnerability allows a local user to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A local user can bypass authentication process and gain unauthorized access to the application by conducting a row hammer attack against the mm_answer_authpassword integer value to flip a single bit.
Affected software
IBM Security Verify Access
IBM Qradar SIEM
Verify Identity Access Digital Credentials
Storage Protect Plus Server
IQ Engine
IBM Integrated Analytics System
Dell Secure Connect Gateway
RecoverPoint for VMs
How to mitigate CVE-2023-51767
IBM Integrated Analytics System - update to 1.0.30.0
Dell Secure Connect Gateway - update to 5.24.00.14
RecoverPoint for VMs - update to 6.0.SP1.P1
Storage Protect Plus Server - update to 10.1.16.2
External References
- https://arxiv.org/abs/2309.02545
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/monitor.c#L878
- https://github.com/openssh/openssh-portable/blob/8241b9c0529228b4b86d88b1a6076fb9f97e4a99/auth-passwd.c#L77
- https://bugzilla.redhat.com/show_bug.cgi?id=2255850
- https://access.redhat.com/security/cve/CVE-2023-51767
- https://ubuntu.com/security/CVE-2023-51767
- https://security.netapp.com/advisory/ntap-20240125-0006/
Related Security Bulletins
- Improper authentication in IBM QRadar SIEM
- Multiple vulnerabilities in Dell Secure Connect Gateway
- Multiple vulnerabilities in Storage Protect Plus Server
- IBM Integrated Analytics System update for OpenSSH
- Multiple vulnerabilities in Dell RecoverPoint for Virtual Machines
- ExtremeCloud IQ Site Engine update for OpenSSH
- Multiple vulnerabilities in IBM Verify Identity Access and IBM Security Verify Access