← All CVEs NewScan detects
high

CVE-2023-38408

OpenSSH ssh-agent PKCS#11 provider remote code execution (agent forwarding to a hostile host)

Severity
high
Affected product
OpenSSH
Affected versions
OpenSSH < 9.3
Fixed in
OpenSSH 9.3p2
Added to NewScan
2026-08-02
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints OpenSSH from its response and reports this CVE when the detected version falls inside the affected range below.

Deliberately narrowed: the fix is 9.3p2, and the banner's patch level (p1/p2) is not part of the extracted version, so gating on <9.4 would flag patched 9.3p2 hosts. Under-reports 9.3p1 rather than producing a false positive.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →