Vulnerability record · CVE-2023-38408 · published 20 July 2023
CVE-2023-38408: OpenSSH ssh-agent PKCS#11 search path flaw enables RCE via agent forwarding
Openbsd · Openssh
The PKCS#11 support in ssh-agent in OpenSSH before 9.3p2 uses an insufficiently trustworthy search path, so code loaded from locations such as /usr/lib is not necessarily safe to load into the agent. Because this is an incomplete fix for CVE-2016-10009, an attacker who controls a system to which an agent is forwarded can abuse the forwarded agent to execute code on the victim's machine.
Description
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no privileges or interaction required, and public exploit references make this a high-impact remote code execution flaw.
What it is
The PKCS#11 support in ssh-agent in OpenSSH before 9.3p2 uses an insufficiently trustworthy search path, so code loaded from locations such as /usr/lib is not necessarily safe to load into the agent. Because this is an incomplete fix for CVE-2016-10009, an attacker who controls a system to which an agent is forwarded can abuse the forwarded agent to execute code on the victim's machine.
Impact
An attacker gains remote code execution in the context of the user running the forwarded ssh-agent, which can expose the victim's SSH keys and any host the agent can authenticate to.
Attack surface
Reached over the network through SSH agent forwarding when the victim connects to an attacker-controlled host; no authentication or user interaction beyond the forwarding connection is required per the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.797 probability, 99.587 percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade OpenSSH to 9.3p2 or later, or apply the vendor patches referenced in the advisory.
- Disable SSH agent forwarding (ForwardAgent no) unless strictly required.
- Restrict agent forwarding to trusted hosts and avoid forwarding to systems you do not control.
- Where PKCS#11 is not needed, remove or disable PKCS#11 provider libraries from the agent's search path.
- Monitor vendor advisories (OpenBSD, Fedora, Debian, Gentoo, Apple, NetApp) for backported fixes.
Detection
- Audit ssh_config and sshd_config for ForwardAgent and AllowAgentForwarding settings across managed hosts.
- Monitor ssh-agent processes for unexpected loading of PKCS#11 provider libraries from unusual paths.
- Alert on outbound SSH sessions to untrusted or newly seen hosts where agent forwarding is enabled.
- Review endpoint logs for child processes spawned by ssh-agent that are not expected.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-38408 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-38408), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.