VDB

CVE-2023-38408

CVE-2023-38408 PUBLISHED CVSS 8.800000190734863 HIGH

Vulnerability in the PKCS#11 feature of ssh-agent in OpenSSH versions before 9.3p2. It involves an insufficiently trustworthy search path, which can lead to remote code execution if an agent is forwarded by authenticated user to an attacker-controlled system.

EPSS 64.35% · 98.5th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:W/RC:C
EPSS Score
64.35%
98.5th percentile

Affected Products

VendorProductVersions
ABBABB M2M Gateway ARM600, firmware versions >=4.1.2|<=5.0.3
ABBABB M2M Gateway SW, software versions >=5.0.1|<=5.0.3

Timeline

  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 20, 1970 VulnCheck XDB Entry
  • Jan 21, 1970 VulnCheck XDB Entry
  • Jan 21, 1970 VulnCheck XDB Entry
  • Jul 19, 2023 CVE Published
  • Jul 20, 2023 EPSS Score
  • Jul 26, 2023 VulnCheck KEV Exploitation
  • Nov 8, 2023 EPSS Score
  • Feb 8, 2024 PoC Published
  • Jul 1, 2024 VulnCheck KEV Exploitation
  • Aug 21, 2024 EPSS Score
  • Dec 17, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›