Customers have inquired whether Symantec Messaging Gateway (SMG) is vulnerable to CVE-2023-51384, an OpenSSH vulnerability related to ssh-agent destination constraints.
CVE-2023-51384 describes a flaw in OpenSSH where certain destination constraints can be incompletely applied when multiple keys are returned from a PKCS#11 token. This vulnerability specifically affects OpenSSH versions 8.9 through 9.5.
Symantec Messaging Gateway is not vulnerable to CVE-2023-51384.
This determination is based on the following:
ssh-agent destination constraints or configurations (such as restricted PKCS#11 tokens) required to trigger this vulnerability.As a best practice, Broadcom recommends that customers always maintain their Messaging Gateway environment on the latest available release to ensure they have the most recent security updates and performance improvements.