CVE-2023-51384 & CVE-2023-51385 Impact on PAM
search cancel

CVE-2023-51384 & CVE-2023-51385 Impact on PAM

book

Article ID: 374344

calendar_today

Updated On:

Products

CA Privileged Access Manager (PAM)

Issue/Introduction

OpenSSH has vulnerabilities CVE-2023-51384 and CVE-2023-51385 which are resolved in version 9.6 and above. Is PAM impacted by these two vulnerabilities?

Resolution

PAM is not impacted by either vulnerability for the following reasons.

For CVE-2023-51384, the OpenSSH ssh-agent client code which is vulnerable is not used within the PAM software.
For CVE-2023-51385, the vulnerable ProxyCommand component is disabled by default in OpenSSH and PAM does not enable it.