ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
2023-03-17T04:15:14.553
2025-11-04T19:15:41.430
Modified
CVSSv3.1: 9.8 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | openbsd | openssh | < 9.3 | Yes |
| Operating System | netapp | brocade_fabric_operating_system | - | Yes |
| Operating System | netapp | hci_bootstrap_os | - | Yes |
| Operating System | netapp | solidfire_element_os | - | Yes |