PatchSiren cyber security CVE debrief
CVE-2023-28531 Netapp CVE debrief
CVE-2023-28531 is a critical OpenSSH issue in which ssh-add can add smartcard keys to ssh-agent without the intended per-hop destination constraints. The supplied corpus says the earliest affected version is 8.9, and NVD lists the vulnerable OpenSSH range as 8.9 through 9.2. Because the issue touches SSH authentication and agent key handling, organizations that rely on constrained agent workflows should treat this as a high-priority patch item.
- Vendor
- Netapp
- Product
- Unknown
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-06-10
- Original CVE updated
- 2026-05-14
- Advisory published
- 2025-06-10
- Advisory updated
- 2026-05-14
Who should care
Administrators and users of OpenSSH 8.9-9.2, especially environments using ssh-agent, smartcard-backed keys, jump hosts, bastions, or per-hop SSH restrictions. Also review downstream appliances or distributions that ship OpenSSH or backported fixes, including the NetApp-related CPEs listed by NVD.
Technical summary
The source description states that ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. NVD’s version data narrows the affected range to 8.9 inclusive through 9.3 exclusive. The provided CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a critical impact profile. The corpus also lists several NetApp CPEs alongside OpenSSH, so downstream product exposure should be checked rather than assuming upstream-only impact.
Defensive priority
Urgent. The published severity is Critical (9.8), the issue affects a core SSH trust boundary, and the corpus indicates no privilege or user interaction is required. Patch or upgrade as soon as possible, and do not rely on constrained-agent controls until remediation is verified.
Recommended defensive actions
- Upgrade OpenSSH to 9.3 or later on all affected systems.
- Audit hosts and appliances for OpenSSH 8.9-9.2 or downstream packages that may include backported code.
- Review any use of ssh-agent with smartcard keys and per-hop destination constraints, especially on bastions and jump hosts.
- Prioritize remediation on internet-reachable SSH infrastructure and administrative endpoints first.
- Apply vendor-specific advisories for downstream products listed in the source corpus, including NetApp-related advisories and distro notices.
- Verify patch status across Linux distributions and appliances rather than relying on package names alone.
Evidence notes
The supplied corpus names OpenSSH before 9.3 as affected and states the earliest affected version is 8.9. NVD’s CPE criteria specify OpenSSH 8.9 through 9.3 exclusive. The corpus does not provide exploit code or confirm active exploitation, and KEV is absent. Because the supplied vendor field says Netapp while the primary vulnerability description names OpenSSH, this debrief treats OpenSSH as the primary affected component and notes the NetApp CPE entries only as listed in NVD.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-28531 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-28531
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-28531 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-28531
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.gentoo.org/glsa/202307-01
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://security.netapp.com/advisory/ntap-20230413-0008/
[email protected] - Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://www.debian.org/security/2023/dsa-5586
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.openwall.com/lists/oss-security/2023/03/15/8
[email protected] - Mailing List, Release Notes
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/[email protected]/message/AN2UDTXEUSKFIOIYMV6JNI5VSBMYZOFT/
af854a3a-2127-422b-91ae-364da2661108
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-082556.html
0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.