CVE-2023-51767: a bogus CVE in OpenSSH

Published Dec 24, 2023
·
Updated

Last updated 24 September 2025

Other sources

OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mmanswerauthpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."

MITRE

OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mmanswerauthpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.

Launchpad

Affected Software

5 affected components
F5 Traffix SDC=5.2.0, =5.1.0
OpenBSD OpenSSH
Fedoraproject Fedora=39
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Disable password-based authentication in sshd_config (set PasswordAuthentication no) to avoid relying on the mm_answer_authpassword code path referenced in the advisory.

    OpenSSH PasswordAuthentication = no
  2. Compensating control

    Mitigate the row-hammer co-location threat model by preventing untrusted/guest users from being co-located with targets (use isolation between tenants/VMs/containers) and by deploying hardware/platform mitigations where possible (use DRAM with protections such as ECC or vendor-provided row-hammer mitigations).

  3. Operational

    Inventory deployed systems (including F5 Traffix Systems Signaling Delivery Controller instances) to determine whether they include OpenSSH installations 'through 10.0' or 'through 9.6' and identify servers allowing password authentication.

  4. Operational

    There are no already-known fixed versions (ALREADY-KNOWN FIXED VERSIONS: (none)). Monitor upstream OpenSSH and vendor/supplier advisories for any future patches or official guidance and plan to apply vendor-supplied fixes when they become available.

  5. Operational

    If password authentication cannot be disabled immediately, restrict SSH access via network controls (restrict source IPs, require jump hosts) and require stronger authentication (public-key only) where possible until a vendor patch or alternative mitigation is applied.

Event History

Dec 24, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityAffected Software
Dec 25, 2023
Data Sourced
via Red Hat·07:41 PM
DescriptionSeverityAffected Software
Feb 17, 2024
Advisory Published
via F5·12:27 AM
Sep 26, 2025
Data Sourced
via Ubuntu·04:47 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·04:48 PM
Description
Data Sourced
via Debian·04:48 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-51767?

CVE-2023-51767 is considered to have a moderate severity due to the potential for authentication bypass via row hammer attacks.

2

How do I fix CVE-2023-51767?

To mitigate CVE-2023-51767, upgrade OpenSSH to a version later than 9.6 that addresses this vulnerability.

3

Which software is affected by CVE-2023-51767?

CVE-2023-51767 affects OpenSSH versions up to and including 9.6, as well as specific versions of F5 Traffix SDC.

4

Can CVE-2023-51767 allow an attacker to bypass authentication?

Yes, CVE-2023-51767 may allow an attacker to bypass authentication under certain conditions due to a flaw in the authentication process.

5

What are row hammer attacks in relation to CVE-2023-51767?

Row hammer attacks exploit bit flips in DRAM to manipulate data, potentially allowing unauthorized access in the context of CVE-2023-51767.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203