HPE OneView
1820700 Members
2520 Online
109627 Solutions
New Discussion

Is CVE-2023-38408 fixed?

 
SOLVED
Go to solution
rd-Linux
Regular Visitor

Is CVE-2023-38408 fixed?

Dear all,

is CVE-2023-38408 (CVE - CVE-2023-38408 (mitre.org)) already fixed, and if so, in which version?

Although we are running the latest version 9.0, our security scanner is referring to that CVE, since it detects an openssh version 7.4 inside the oneview appliance. I could not find any information about that CVE, neither in this forum nor on the internet.

Best regards

rd-Linux

3 REPLIES 3
DanCernese
HPE Pro

Re: Is CVE-2023-38408 fixed?

The only official communication is found here: https://support.hpe.com/hpesc/public/docDisplay?docId=sd00001284en_us&page=GUID-F7F6CB78-93EF-4F6F-8B45-B3847F06A9AB.html

CVE-2023-38408:
HPE OneView does not support SSH forwarding so its not affected, again false positive based only on openssh version

All scanners that report solely based on version will trigger many false positives where HPE OneView is not vulnerable.



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
ChrisLynch
HPE Pro
Solution

Re: Is CVE-2023-38408 fixed?

Additionally, we are working on an Advisory stating neither OneView or OneView Global Dashboard are impacted by this CVE. The scan result is a false positive.
I work at HPE
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
rd-Linux
Regular Visitor

Re: Is CVE-2023-38408 fixed?

Thanks for your replies.

As suggested, we will mark that finding as a false-positive.