CVE-2023-5616

In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*
cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*

History

26 Aug 2025, 16:34

Type Values Removed Values Added
References () https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577 - () https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577 - Exploit, Issue Tracking
References () https://ubuntu.com/security/CVE-2023-5616 - () https://ubuntu.com/security/CVE-2023-5616 - Vendor Advisory
References () https://ubuntu.com/security/notices/USN-6554-1 - () https://ubuntu.com/security/notices/USN-6554-1 - Vendor Advisory
First Time Canonical
Canonical ubuntu Linux
Gnome control Center
Gnome
CPE cpe:2.3:o:canonical:ubuntu_linux:23.04:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:*
cpe:2.3:a:gnome:control_center:*:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:22.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:23.10:*:*:*:*:*:*:*

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) En Ubuntu, gnome-control-center no reflejaba correctamente el estado de inicio de sesión remoto SSH cuando el sistema estaba configurado para usar la activación del socket systemd para openssh-server. Esto podía dejar, sin que el usuario lo supiera, la máquina local expuesta al acceso remoto SSH, contrariamente a lo esperado.

15 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-290
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.9

15 Apr 2025, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 19:16

Updated : 2025-08-26 16:34


NVD link : CVE-2023-5616

Mitre link : CVE-2023-5616

CVE.ORG link : CVE-2023-5616


JSON object : View

Products Affected

gnome

  • control_center

canonical

  • ubuntu_linux
CWE
CWE-290

Authentication Bypass by Spoofing