- Description
- The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
- Source
- cve@mitre.org
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- Hype score
- Not currently trending
MOXA 産業用スイッチに致命的な脆弱性(CVE-2023-38408) https://t.co/EvC1vfFu1e
@cybersecnews_jp
15 Jan 2026
24 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
MOXA 産業用スイッチに致命的な脆弱性(CVE-2023-38408) https://t.co/1czEefTLYb #セキュリティ対策Lab #セキュリティ #Security
@securityLab_jp
15 Jan 2026
108 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I just completed CVE-2023-38408 room on TryHackMe! Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). https://t.co/1qDWmzImzx #tryhackme via @tryhackme
@Saffi_Nawaz
14 Jan 2026
0 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I did "CVE-2023-38408" for my 831st @tryhackme room! This one was pretty wild I am still working on it and trying to understand it better. https://t.co/7Z0PtCmM6q
@NapaCorruption
14 Jan 2026
69 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2023-38408: OpenSSH Vulnerability in Ethernet Switches URL: https://t.co/SJIAXGpknq Classification: Critical, Solution: Official Fix, Exploit Maturity: Functional, CVSSv3.1: 9.8
@samilaiho
12 Jan 2026
175 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
I just completed CVE-2023-38408 room on TryHackMe! Learn how to move laterally abusing libraries' side effects in Ubuntu (CVE-2023-38408). https://t.co/wg0M4YUTKn #tryhackme via @tryhackme
@Shyam48973Yadav
12 Jan 2026
53 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2023-38408: Critical OpenSSH ssh-agent flaw (CVSS 9.8) allows remote code execution via malicious libraries. AccuKnox Zero Trust CNAPP & KubeArmor: -Block unauthorized library loads in real time -Monitor SSH activity & detect anomalies -Contain lateral movement
@AccuKnox
13 Nov 2025
67 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️Actualizaciones de seguridad para los productos de Juniper ❗CVE-2023-38408 ❗CVE-2024-47538 ❗CVE-2019-12900 ❗CVE-2025-59964 ➡️Más info: https://t.co/rHxl8RhXIn https://t.co/2wT2YyImtU
@CERTpy
13 Oct 2025
113 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[https://t.co/PIEOWDc22Z 94.152.58.192] dalej 94.152.152.228 TCP 22 CVE-2023-38408, CVE-2023-28531 Znowu na dnie Wisły? https://t.co/WEMEb4S9jT https://t.co/9cK0kwRKjO https://t.co/6cAggkhBv9
@KulinskiArkadi
3 Sept 2025
76 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
0 Quotes
VGT INTERNET https://t.co/WDRryJO1q7 94.152.39.1 CVE-2023-38408 CVE-2023-28531 https://t.co/y7iFul3pRo https://t.co/xTYoUPMCMG
@KulinskiArkadi
14 May 2025
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
GitHub - TX-One/CVE-2023-38408: CVE-2023-38408 SSH Vulnerability Scanner & PoC https://t.co/QsjlE8eMT5
@akaclandestine
19 Apr 2025
1030 Impressions
0 Retweets
8 Likes
3 Bookmarks
0 Replies
0 Quotes
https://t.co/fpKSbL0UyR Day 15 of learning &exploiting cve-2023-38408 on #tryhackme for #cybersecurity
@hiro001_gofone
27 Feb 2025
27 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
CVE-2023-38408 how to. https://t.co/EWujmRnigu https://t.co/eZsJX5HBo8
@secharvesterx
22 Feb 2025
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*",
"matchCriteriaId": "BF546253-FE80-4416-A138-D79D7288229F",
"versionEndExcluding": "9.3",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:openbsd:openssh:9.3:-:*:*:*:*:*:*",
"matchCriteriaId": "031E80CD-A7CF-447A-AEEF-EB97EB99A762",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:openbsd:openssh:9.3:p1:*:*:*:*:*:*",
"matchCriteriaId": "97FEC052-52ED-464F-AF19-3621775292D6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
"matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*",
"matchCriteriaId": "CC559B26-5DFC-4B7A-A27C-B77DE755DFF9",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]