CVE-2023-28531: Netapp Brocade Fabric Operating System
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
Affected products
- Netapp Brocade Fabric Operating System: affected versions not specified
- Netapp Hci Bootstrap OS: affected versions not specified
- Netapp Solidfire Element OS: affected versions not specified
- OpenBSD OpenSSH: from 8.9, before 9.3 (fixed in 9.3)
Published 2023-03-17. Last modified 2026-07-14.