CVE-2023-38408

CVE-2023-38408: Critical Remote Code Execution Vulnerability in OpenSSH

Image
by  |  November 11, 2025  |  8 minutes

A critical remote code execution vulnerability (CVE-2023-38408) in OpenSSH ssh-agent affects versions prior to 9.3p2 through PKCS#11 feature exploitation. This vulnerability, with a CVSS score of 9.8, enables attackers to execute arbitrary code via SSH agent forwarding and shared library manipulation in enterprise SSH infrastructure.