CVE-2023-51385
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 19.8%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 19.75% probability · 97th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- openbsd/openssh · debian/debian linux
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2024/Mar/21
- http://www.openwall.com/lists/oss-security/2023/12/26/4Mailing List, Third Party Advisory
- https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1aPatch
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202312-17Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240105-0005/
- https://support.apple.com/kb/HT214084
- https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.htmlThird Party Advisory
- https://www.debian.org/security/2023/dsa-5586Third Party Advisory
- https://www.openssh.com/txt/release-9.6Release Notes
- https://www.openwall.com/lists/oss-security/2023/12/18/2Mailing List, Release Notes
- http://seclists.org/fulldisclosure/2024/Mar/21
- http://www.openwall.com/lists/oss-security/2023/12/26/4Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2025/10/07/1
- http://www.openwall.com/lists/oss-security/2025/10/12/1
- https://github.com/openssh/openssh-portable/commit/7ef3787c84b6b524501211b11a26c742f829af1aPatch
- https://lists.debian.org/debian-lts-announce/2023/12/msg00017.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/202312-17Third Party Advisory
- https://security.netapp.com/advisory/ntap-20240105-0005/
- https://support.apple.com/kb/HT214084
- https://vin01.github.io/piptagole/ssh/security/openssh/libssh/remote-code-execution/2023/12/20/openssh-proxycommand-libssh-rce.htmlThird Party Advisory
- https://www.debian.org/security/2023/dsa-5586Third Party Advisory
- https://www.openssh.com/txt/release-9.6Release Notes
- https://www.openwall.com/lists/oss-security/2023/12/18/2Mailing List, Release Notes
- https://cert-portal.siemens.com/productcert/html/ssa-082556.html
- https://cert-portal.siemens.com/productcert/html/ssa-769027.html
- https://cert-portal.siemens.com/productcert/html/ssa-794697.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.