Symantec Messaging Gateway impact for OpenSSH vulnerability (CVE-2023-38408)
search cancel

Symantec Messaging Gateway impact for OpenSSH vulnerability (CVE-2023-38408)

book

Article ID: 443553

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Vulnerability scanners may report that Symantec Messaging Gateway (SMG) is running a version of OpenSSH that is susceptible to CVE-2023-38408.

This CVE involves a condition where specific libraries loaded via ssh-agent's PKCS#11 support could be abused to achieve remote code execution via a forwarded agent socket.

Environment

  • Product: Messaging Gateway (SMG)
  • Version: 10.9.0 and later

Cause

Vulnerability scanners typically perform version-based checks rather than active penetration testing. While the underlying OpenSSH version may be identified as older than 9.3p2 (the version where the fix was introduced upstream), the specific components and configurations required to exploit this vulnerability are not present in the hardened Messaging Gateway architecture.

Resolution

Symantec Messaging Gateway is not vulnerable to CVE-2023-38408.

The vulnerability cannot be exploited on SMG for the following reasons:

  • No SSH-Agent usage: The SMG appliance does not start or utilize instances of ssh-agent.
  • Restricted CLI: The administrative CLI does not provide the capability to leverage PKCS#11 or initiate the agent forwarding required to trigger this condition.
  • Hardened Architecture: SMG is a "black box" appliance where internal components are restricted. Users cannot load arbitrary libraries into the system memory or modify the SSH configuration to enable the vulnerable path.

No further action or patching is required to address this specific CVE on Messaging Gateway 10.9.0 or later.

Additional Information