« Volver al listado

CVE-2023-5616

Estado: AnalizadaMedia (4.9)—

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-5616",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-5616",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-15T20:51:27.350779Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.9,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.4
      }
    ]
  },
  "affected": [
    {
      "source": "security@ubuntu.com",
      "affectedData": [
        {
          "repo": "https://git.launchpad.net/ubuntu/+source/gnome-remote-desktop",
          "vendor": "Canonical Ltd.",
          "product": "Ubuntu's gnome-control-center",
          "versions": [
            {
              "status": "affected",
              "version": "1:45",
              "lessThan": "1:45.0-1ubuntu3.1",
              "versionType": "deb"
            },
            {
              "status": "affected",
              "version": "1:44",
              "lessThan": "1:44.0-1ubuntu6.1",
              "versionType": "deb"
            },
            {
              "status": "affected",
              "version": "1:41",
              "lessThan": "1:41.7-0ubuntu0.22.04.8",
              "versionType": "deb"
            },
            {
              "status": "affected",
              "version": "1:3",
              "lessThan": "1:3.36.5-0ubuntu4.1",
              "versionType": "deb"
            }
          ],
          "platforms": [
            "Linux"
          ],
          "packageName": "Ubuntu's gnome-control-center"
        }
      ]
    }
  ],
  "published": "2025-04-15T19:16:06.647",
  "references": [
    {
      "url": "https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577",
      "tags": [
        "Exploit",
        "Issue Tracking"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://ubuntu.com/security/CVE-2023-5616",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    },
    {
      "url": "https://ubuntu.com/security/notices/USN-6554-1",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@ubuntu.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-290"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user."
    },
    {
      "lang": "es",
      "value": "En Ubuntu, gnome-control-center no reflejaba correctamente el estado de inicio de sesión remoto SSH cuando el sistema estaba configurado para usar la activación del socket systemd para openssh-server. Esto podía dejar, sin que el usuario lo supiera, la máquina local expuesta al acceso remoto SSH, contrariamente a lo esperado."
    }
  ],
  "lastModified": "2026-06-17T06:48:56.980",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D445DCBB-103C-4744-9DE2-1FF15664C377",
              "versionEndExcluding": "1.3.36.5-0ubuntu4.1",
              "versionStartIncluding": "1.3"
            },
            {
              "criteria": "cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D403A617-1667-4411-8FF5-C1CEA3F642A1",
              "versionEndExcluding": "1.41.7-0ubuntu0.22.04.8",
              "versionStartIncluding": "1.41"
            },
            {
              "criteria": "cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1BDC6FC6-2448-47F8-BD6E-B38E298B59DB",
              "versionEndExcluding": "1.44.0-1ubuntu6.1",
              "versionStartIncluding": "1.44"
            },
            {
              "criteria": "cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED923FAF-6322-412B-B9C0-230E9B1A9A21",
              "versionEndExcluding": "1.45.0-1ubuntu3.1",
              "versionStartIncluding": "1.45"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "902B8056-9E37-443B-8905-8AA93E2447FB"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "359012F1-2C63-415A-88B8-6726A87830DE"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B2E702D7-F8C0-49BF-9FFB-883017076E98"
            },
            {
              "criteria": "cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "602CE21C-E1A9-4407-A504-CF4E58F596F5"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@ubuntu.com"
}