high
CVE-2023-38408
OpenSSH ssh-agent PKCS#11 provider remote code execution (agent forwarding to a hostile host)
- Severity
- high
- Affected product
- OpenSSH
- Affected versions
- OpenSSH < 9.3
- Fixed in
- OpenSSH 9.3p2
- Added to NewScan
- 2026-08-02
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints OpenSSH from its response and reports this CVE when the detected version falls inside the affected range below.
Deliberately narrowed: the fix is 9.3p2, and the banner's patch level (p1/p2) is not part of the extracted version, so gating on <9.4 would flag patched 9.3p2 hosts. Under-reports 9.3p1 rather than producing a false positive.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →