CVE-2025-32728

MEDIUM

OpenSSH <10.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.

Scores

CVSS v3 4.3
EPSS 0.0022
EPSS Percentile 44.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-440
Status published
Products (2)
debian/debian_linux 11.0
openbsd/openssh 7.4 - 10.0
Published Apr 10, 2025
Tracked Since Feb 18, 2026