gnome-control-center: Remote login misconfiguration in GNOME Control Center
Published Apr 15, 2025
4.9
MEDIUMCVSS 3.1
EPSS 0.23%
Description
In Ubuntu, gnome-control-center did not properly reflect SSH remote login status when the system was configured to use systemd socket activation for openssh-server. This could unknowingly leave the local machine exposed to remote SSH access contrary to expectation of the user.
Affected products
-
- Version 1:3StatusaffectedConstraints<1:3.36.5-0ubuntu4.1
- Version 1:41StatusaffectedConstraints<1:41.7-0ubuntu0.22.04.8
- Version 1:44StatusaffectedConstraints<1:44.0-1ubuntu6.1
- Version 1:45StatusaffectedConstraints<1:45.0-1ubuntu3.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Canonical Ltd. | Ubuntu's gnome-control-center | n/a |
|
Configuration 1
- ≥ 1.3 · < 1.3.36.5-0ubuntu4.1
- ≥ 1.41 · < 1.41.7-0ubuntu0.22.04.8
- ≥ 1.44 · < 1.44.0-1ubuntu6.1
- ≥ 1.45 · < 1.45.0-1ubuntu3.1
Configuration 2
- 20.04
- 22.04
- 23.04
- 23.10
No data.
Red Hat Enterprise Linux 10
gnome-control-center
Fix deferred
Red Hat Enterprise Linux 8
gnome-control-center
Fix deferred
Red Hat Enterprise Linux 9
gnome-control-center
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | gnome-control-center | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | gnome-control-center | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | gnome-control-center | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 15, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.23% (0.00232) | 12.73th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.19% (0.00195) | 9.29th | v5 (v2026.06.15) |
| Apr 16, 2025 | 0.06% (0.00060) | 18.82th | v4 (v2025.03.14) |
References (7)
- https://access.redhat.com/security/cve/CVE-2023-5616 Vendor Advisory
- https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577 issue-trackingExploitIssue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2359838 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2023-5616
- https://ubuntu.com/security/CVE-2023-5616 issue-trackingVendor Advisory
- https://ubuntu.com/security/notices/USN-6554-1 vendor-advisoryVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2023-5616
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-5616 | Vendor Advisory | |
| https://bugs.launchpad.net/ubuntu/+source/gnome-control-center/+bug/2039577 | issue-trackingExploitIssue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2359838 | Issue Tracking | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-5616 | ||
| https://ubuntu.com/security/CVE-2023-5616 | issue-trackingVendor Advisory | |
| https://ubuntu.com/security/notices/USN-6554-1 | vendor-advisoryVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2023-5616 |
Change history (0)
No recorded changes yet.