Does vulnerability CVE-2023-51384 impact Symantec Messaging Gateway?
search cancel

Does vulnerability CVE-2023-51384 impact Symantec Messaging Gateway?

book

Article ID: 443556

calendar_today

Updated On:

Products

Messaging Gateway

Issue/Introduction

Customers have inquired whether Symantec Messaging Gateway (SMG) is vulnerable to CVE-2023-51384, an OpenSSH vulnerability related to ssh-agent destination constraints.

Environment

  • Product: Messaging Gateway (SMG)
  • Version: All versions

Cause

CVE-2023-51384 describes a flaw in OpenSSH where certain destination constraints can be incompletely applied when multiple keys are returned from a PKCS#11 token. This vulnerability specifically affects OpenSSH versions 8.9 through 9.5.

Resolution

Symantec Messaging Gateway is not vulnerable to CVE-2023-51384.

This determination is based on the following:

  • OpenSSH Version: SMG utilizes system packages based on a secure enterprise Linux foundation. The OpenSSH versions included in these packages are earlier than version 8.9, which is when the affected destination constraint functionality was first introduced.
  • Configuration: SMG does not utilize the specific ssh-agent destination constraints or configurations (such as restricted PKCS#11 tokens) required to trigger this vulnerability.

As a best practice, Broadcom recommends that customers always maintain their Messaging Gateway environment on the latest available release to ensure they have the most recent security updates and performance improvements.

Additional Information