CVE-2023-5616

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
canonicalCNA
---
---
CISA-ADPADP
4.9 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
VendorProductVersion
gnomecontrol_center
1.3 ≤
𝑥
< 1.3.36.5-0ubuntu4.1
gnomecontrol_center
1.41 ≤
𝑥
< 1.41.7-0ubuntu0.22.04.8
gnomecontrol_center
1.44 ≤
𝑥
< 1.44.0-1ubuntu6.1
gnomecontrol_center
1.45 ≤
𝑥
< 1.45.0-1ubuntu3.1
canonicalubuntu_linux
20.04
canonicalubuntu_linux
22.04
canonicalubuntu_linux
23.04
canonicalubuntu_linux
23.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gnome-control-center
bullseye
no-dsa
bookworm
postponed
buster
no-dsa
sid
vulnerable
trixie
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gnome-control-center
oracular
Fixed 1:45.0-1ubuntu4
released
noble
Fixed 1:45.0-1ubuntu4
released
mantic
Fixed 1:45.0-1ubuntu3.1
released
lunar
Fixed 1:44.0-1ubuntu6.1
released
jammy
Fixed 1:41.7-0ubuntu0.22.04.8
released
focal
Fixed 1:3.36.5-0ubuntu4.1
released
bionic
needs-triage
xenial
needs-triage
trusty
ignored