CVE-2023-28531: Netapp Brocade Fabric Operating System

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.

Affected products

  • Netapp Brocade Fabric Operating System: affected versions not specified
  • Netapp Hci Bootstrap OS: affected versions not specified
  • Netapp Solidfire Element OS: affected versions not specified
  • OpenBSD OpenSSH: from 8.9, before 9.3 (fixed in 9.3)

Published 2023-03-17. Last modified 2026-07-14.