Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-5616

Опубликовано: 15 апр. 2025
Источник: redhat
CVSS3: 4.9
EPSS Низкий

Описание

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

A flaw was found in the GNOME Control Center. This vulnerability allows the SSH service to be improperly enabled without properly managing systemd units, which could unintentionally expose remote login access through insecure service activation management.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10gnome-control-centerFix deferred
Red Hat Enterprise Linux 8gnome-control-centerFix deferred
Red Hat Enterprise Linux 9gnome-control-centerFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2359838gnome-control-center: Remote login misconfiguration in GNOME Control Center

EPSS

Процентиль: 8%
0.00028
Низкий

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
10 месяцев назад

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

CVSS3: 4.9
nvd
10 месяцев назад

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

CVSS3: 4.9
debian
10 месяцев назад

In Ubuntu, gnome-control-center did not properly reflect SSH remote lo ...

CVSS3: 4.9
github
10 месяцев назад

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

EPSS

Процентиль: 8%
0.00028
Низкий

4.9 Medium

CVSS3