CVE-2023-28531
Critical · CVSS 9.8OpenSSH ssh-add — Improper Access Control - smartcard keys added to ssh-agent without per-hop destination constraints
- CVSS
- 9.8
- nvd
- EPSS
- 2.22%
- 81th pct
- KEV
- No
- Class
- oss containerizable
- NVD-CWE-noinfo, CWE-284
Description
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Search profile — drives PoC discovery
Symbols ssh-addssh-agentsmartcarddestination constraintsSSH_AGENT_CONSTRAIN_DESTINATIONadd_smartcard_keyssh_add_identity_constrainedSSH_AGENTC_ADD_SMARTCARD_KEY_CONSTRAINED
Keywords CVE-2023-28531OpenSSHssh-addsmartcardssh-agentdestination constraintsper-hop8.99.3improper access controlPoCproof of concept
Versions: 8.9 <= OpenSSH < 9.3
Ranked PoCs (15) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
- ★ 0Certifiedhustler-Swaba/VulnerableGPT needs reviewtrickest
- ★ 0DishanyaaShriiKM7/Elevate_Labs_Task_3 needs reviewtrickest
- ★ 0GitHubForSnap/openssh-server-gael needs reviewtrickest
- ★ 0Raj-h-hacker/GPT_Vuln-analyzer needs reviewtrickest
- ★ 0SourcePointSecurity/SwampScan needs reviewtrickest
- ★ 0Spyr026/Proyecto-Ciberseguridad needs reviewtrickest
- ★ 0akashkannancybersec/Echothreat needs reviewtrickest
- ★ 0alvarigno22/NodeClimb-DockerLab needs reviewtrickest
- ★ 0blessing-gao/SecurityPatcher needs reviewtrickest
- ★ 0byfranke/Estudo_de_Casos_HdB needs reviewtrickest
- ★ 0drg3nz0/gpt-analyzer needs reviewtrickest
- ★ 0fkie-cad/nvd-json-data-feeds needs reviewtrickest
- ★ 0morpheuslord/GPT_Vuln-analyzer needs reviewtrickest
- ★ 0nzelyn/GPT_Vuln-analyzer needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://security.gentoo.org/glsa/202307-01
- https://security.netapp.com/advisory/ntap-20230413-0008/
- https://www.debian.org/security/2023/dsa-5586
- https://www.openwall.com/lists/oss-security/2023/03/15/8
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
- https://security.gentoo.org/glsa/202307-01
- https://security.netapp.com/advisory/ntap-20230413-0008/
- https://www.debian.org/security/2023/dsa-5586
- https://www.openwall.com/lists/oss-security/2023/03/15/8
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z