CVE-2025-32728

EUVD-2025-10504
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Affected Products (NVD)
VendorProductVersion
openbsdopenssh
7.4 ≤
𝑥
< 10.0
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
openssh
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-askpass
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
openssh-cavs
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
openssh-clients
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-clients-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-debuginfo
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-debugsource
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-keycat
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-keycat-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-ldap
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
openssh-server
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-server-debuginfo
Amazon Linux 2023
0:8.7p1-8.amzn2023.0.15
fixed
openssh-server-sysvinit
Amazon Linux 2
0:7.4p1-22.amzn2.0.11
fixed
pam_ssh_agent_auth
Amazon Linux 2
0:0.10.3-2.22.amzn2.0.11
fixed
Amazon Linux 2023
0:0.10.4-4.8.amzn2023.0.15
fixed
pam_ssh_agent_auth-debuginfo
Amazon Linux 2023
0:0.10.4-4.8.amzn2023.0.15
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
openssh
Azure Linux 3.0
0:9.8p1-4.azl3
fixed
CBL-Mariner 2.0
0:8.9p1-8.cm2
fixed