Vulnerability Name:

CVE-2021-28041 (CCN-197813)

Assigned:2021-03-02
Published:2021-03-02
Updated:2022-05-20
Summary:ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVSS v3 Severity:7.1 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
7.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)
6.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:4.6 Medium (CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.1 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-415
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2021-28041

Source: XF
Type: UNKNOWN
openssh-cve202128041-sec-bypass(197813)

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/openssh/openssh-portable/commit/e04fd6dde16de1cdc5a4d9946397ff60d96568db

Source: FEDORA
Type: Mailing List, Third Party Advisory
FEDORA-2021-1d3698089d

Source: FEDORA
Type: Third Party Advisory
FEDORA-2021-f68a5a75ba

Source: GENTOO
Type: Third Party Advisory
GLSA-202105-35

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20210416-0002/

Source: CCN
Type: IBM Security Bulletin 6524682 (Spectrum Protect Plus)
Vulnerabilities in Redis, OpenSSH, Golang Go, and Apache Kafka may affect IBM Spectrum Protect Plus Container Backup and Restore for Kubernetes and OpenShift

Source: CCN
Type: OpenSSH Web site
OpenSSH

Source: MISC
Type: Not Applicable, Vendor Advisory
https://www.openssh.com/security.html

Source: MISC
Type: Release Notes, Vendor Advisory
https://www.openssh.com/txt/release-8.5

Source: CCN
Type: oss-sec Mailing List, Tue, 2 Mar 2021 18:19:55 -0700 (MST)
Announce: OpenSSH 8.5 released

Source: MISC
Type: Mailing List, Patch, Third Party Advisory
https://www.openwall.com/lists/oss-security/2021/03/03/1

Source: N/A
Type: Third Party Advisory
N/A

Vulnerable Configuration:Configuration 1:
  • cpe:/a:openbsd:openssh:*:*:*:*:*:*:*:* (Version >= 8.2 and < 8.5)

  • Configuration 2:
  • cpe:/o:fedoraproject:fedora:33:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:34:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:netapp:cloud_backup:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:solidfire:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:hci_management_node:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:netapp:hci_compute_node_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:hci_compute_node:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:netapp:hci_storage_node_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:hci_storage_node:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:oracle:zfs_storage_appliance:8.8:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:communications_offline_mediation_controller:12.0.0.3.0:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:openbsd:openssh:8.4:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:spectrum_protect_plus:10.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_plus:10.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_plus:10.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:spectrum_protect_plus:10.1.8:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8074
    P
    zlib-devel-32bit-1.2.13-150500.2.3 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:7726
    P
    openssh-8.4p1-150300.3.18.2 on GA media (Moderate)
    2023-06-12
    oval:org.opensuse.security:def:3739
    P
    Security update for php7 (Important)
    2022-07-06
    oval:org.opensuse.security:def:3132
    P
    libX11-6-1.6.2-12.5.1 on GA media (Moderate)
    2022-06-28
    oval:org.opensuse.security:def:94762
    P
    openssh-8.4p1-3.9.1 on GA media (Moderate)
    2022-06-22
    oval:org.opensuse.security:def:838
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:99707
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:76434
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:111846
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:94213
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:42250
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:101569
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:69163
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:93593
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1053
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:100034
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:64828
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:94424
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:93119
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:101744
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:99174
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:73950
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:93787
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:1651
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:100368
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:65329
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:4240
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:93280
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:102227
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:99444
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:74397
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:94002
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:100701
    P
    (Important)
    2021-12-22
    oval:org.opensuse.security:def:67366
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:6277
    P
    Security update for openssh (Important)
    2021-12-22
    oval:org.opensuse.security:def:93437
    P
    (Important)
    2021-12-22
    BACK
    openbsd openssh *
    fedoraproject fedora 33
    fedoraproject fedora 34
    netapp cloud backup -
    netapp solidfire -
    netapp hci management node -
    netapp hci compute node firmware -
    netapp hci compute node -
    netapp hci storage node firmware -
    netapp hci storage node -
    oracle zfs storage appliance 8.8
    oracle communications offline mediation controller 12.0.0.3.0
    openbsd openssh 8.4 -
    ibm spectrum protect plus 10.1.5
    ibm spectrum protect plus 10.1.6
    ibm spectrum protect plus 10.1.7
    ibm spectrum protect plus 10.1.8