- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
02-23-2024 01:39 PM
Model | PA-3220 |
Software Version | 10.2.8 |
Qualys scanner reporting OpenSSH Authentication Bypass Vulnerability
Customers are advised to upgrade to OpenSSH 9.6p1 or later to remediate this vulnerability.
Patch
Is this a true issue or false positive?
02-26-2024 08:14 PM
Hi @GaryBrand ,
Is there a CVE included with the vulnerability? With any news regarding vulnerabilities, I would recommend verifying your source as well as researching the associated CVE. Security advisories issued by vendors and researchers almost always mention at least one CVE ID.
If you take a look at OpenSSH security page there is a vulnerability reported on July 19th by the Qualys team that is assigned CVE-2023-38408.
02-26-2024 08:14 PM
Hi @GaryBrand ,
Is there a CVE included with the vulnerability? With any news regarding vulnerabilities, I would recommend verifying your source as well as researching the associated CVE. Security advisories issued by vendors and researchers almost always mention at least one CVE ID.
If you take a look at OpenSSH security page there is a vulnerability reported on July 19th by the Qualys team that is assigned CVE-2023-38408.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!