Vulnerability

CVE-2023-38408

CRITICAL 9.8 patch available

CVE-2023-38408 is a critical-severity vulnerability (CVSS v3.1 9.8). As of 2026-10-05, 1 942 044 hosts in our data show software it affects on an open port in at least 15 countries.

The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.

Published
2023-07-20
Last modified
2024-11-21
CVSS score
9.8 CVSS v3.1
CVSS vector (v3.1)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploit likelihood (EPSS)
Not scored

Exposure in our data

1 942 044 hosts

Hosts whose banner shows an affected software version on a port open at their latest check.

Not counted: 100 589 hosts with this CVE only from an older observation.

Counted 2026-10-05 02:21 UTC

By country

Germany DE425 029
United States US262 691
Netherlands NL177 545
France FR166 006
United Kingdom GB162 047
China CN70 539
Finland FI67 711
Ireland IE44 207
Poland PL40 393
Singapore SG37 322
Hong Kong HK36 990
Spain ES36 131
Italy IT32 360
Sweden SE31 359
Switzerland CH29 262

Affected software seen

openssh 8.9p1530 102
openssh 9.2p1291 387
openssh 7.4185 655
openssh 8.2p1182 297
openssh 8.4p1174 862
openssh 8.7130 996
openssh 8.0112 204
openssh 7.6p165 999
openssh 7.9p151 996
openssh 7.2p228 122
openssh 7.4p122 591
openssh 8.216 534