Vulnerability scanners may report that Symantec Messaging Gateway (SMG) is running a version of OpenSSH that is susceptible to CVE-2023-38408.
This CVE involves a condition where specific libraries loaded via ssh-agent's PKCS#11 support could be abused to achieve remote code execution via a forwarded agent socket.
Vulnerability scanners typically perform version-based checks rather than active penetration testing. While the underlying OpenSSH version may be identified as older than 9.3p2 (the version where the fix was introduced upstream), the specific components and configurations required to exploit this vulnerability are not present in the hardened Messaging Gateway architecture.
Symantec Messaging Gateway is not vulnerable to CVE-2023-38408.
The vulnerability cannot be exploited on SMG for the following reasons:
ssh-agent.No further action or patching is required to address this specific CVE on Messaging Gateway 10.9.0 or later.