Vulnerability
CVE-2023-28531
CRITICAL 9.8
CVE-2023-28531 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 832 898 hosts in our data show software it affects on an open port in at least 15 countries.
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
- Published
- 2023-03-17
- Last modified
- 2026-07-14
- CVSS score
- 9.8 CVSS v3.1
- CVSS vector (v3.1)
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Exploit likelihood (EPSS)
- 2.2% in the next 30 days (higher than 81% of CVEs)
Exposure in our data
832 898 hosts
Hosts whose banner shows an affected software version on a port open at their latest check.
Not counted: 43 665 hosts with this CVE only from an older observation.
Counted 2026-10-05 02:21 UTC
By country
| Germany DE | 211 199 |
| United States US | 94 405 |
| Netherlands NL | 92 224 |
| United Kingdom GB | 70 165 |
| France FR | 69 845 |
| Finland FI | 37 564 |
| Singapore SG | 21 425 |
| Ireland IE | 19 242 |
| Poland PL | 15 458 |
| China CN | 15 144 |
| Hong Kong HK | 13 975 |
| Sweden SE | 13 231 |
| Spain ES | 13 189 |
| Russia RU | 11 853 |
| Switzerland CH | 11 419 |
Affected software seen
| openssh 8.9p1 | 530 102 |
| openssh 9.2p1 | 291 387 |
| openssh 9.0p1 | 4 672 |
| openssh 9.1 | 2 686 |
| openssh 8.9 | 1 785 |
| openssh 9.0 | 1 574 |
| openssh 9.2 | 596 |
| openssh 9.1p1 | 101 |
| openssh 8p2p1 | 1 |