The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
[POC] CVE-2023-38408 — CVE-2023-38408
CVE-2023-38408 Remote Code Execution in OpenSSH's forwarded ssh-agent
[POC] CVE-2023-38408 — cve-2023-38408
An in-depth analysis of CVE 2023 38408, a critical OpenSSH vulnerability, including technical background, exploitation in controlled environments, and mitigation strategies.
[POC] CVE-2023-38408 — cve_2023_38408_scanner
Vulnerability Overview CVE-2023-38408 affects OpenSSH versions < 9.3p2 and stems from improper validation of data when SSH agent forwarding is enabled. When users connect to a remote server with ssh -A, they allow the agent on their local machine to be used for authentication to further systems
[POC] CVE-2023-38408 — nmap-scan-results
Found 200+ vulnerabilities on scanme.nmap.org including CVE-2023-38408 (9.8 critical)
[POC] CVE-2023-38408 — CVE-2023-38408
CVE-2023-38408 Remote Code Execution in OpenSSH's forwarded ssh-agent
[POC] CVE-2023-38408 — CVE-2023-38408
Takeover Account OpenSSH
[POC] CVE-2023-38408 — CVE-2023-38408
PoC for the recent critical vuln affecting OpenSSH versions < 9.3p2
[POC] CVE-2023-38408 — CVE-2023-38408
Script para eliminar vulnerabilidad de openssh de ubuntu 22.04 LTS
[POC] CVE-2023-38408 — CVE-2023-38408
CVE-2023-38408 SSH Vulnerability Scanner & PoC
PoC: CVE-2023-38408
Slide and source code for CS-782 attack presentation
Get alerted for CVEs like this
Register your stack and get notified within minutes when a matching CVE drops.
Start monitoring free