Impact
The sshd service in OpenSSH versions prior to 10.4 contains an undocumented behavior related to the GSSAPIStrictAcceptorCheck setting. When the server is joined to a Windows Active Directory domain, the GSSAPIStrictAcceptorCheck option is effectively omitted, allowing authentication decisions to be made without the intended strict check. This weakness, identified as CWE‑573 (Unused Security Feature), could enable an authenticator that is normally rejected to gain access, potentially allowing unauthorized authentication on the target system.
Affected Systems
The vulnerability impacts OpenBSD's OpenSSH server before version 10.4 and are operating within Windows Active Directory environments.
Risk and Exploitability
The CVSS v3 score of 4.8 reflects a moderate risk posed by this flaw. EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no known public exploitation. Based on the description, it is inferred that the impact is unauthorized authentication, and the likely attack vector is inferred to involve a client attempting GSSAPI authentication within an Active Directory domain. The vulnerability is only exploitable when the server is joined to an Active Directory domain and the attacker can leverage the missing strict check. Because the behavior is undocumented, detection relies on noticing anomalous authentication events.
OpenCVE Enrichment
Ubuntu USN