Back to Database
Status published
Medium
CVE-2025-32728
In sshd in OpenSSH before 10.0, the DisableForwarding directive does...
Vulnerability Description
In sshd in OpenSSH before 10.0, the DisableForwarding directive does not adhere to the documentation stating that it disables X11 and agent forwarding.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-32728
Credits & Attribution
No credits recorded in the NVD database.
References
- https://lists.mindrot.org/pipermail/openssh-unix-dev/2025-April/041879.html
- https://www.openssh.com/txt/release-10.0
- https://github.com/openssh/openssh-portable/commit/fc86875e6acb36401dfc1dfb6b628a9d1460f367
- https://ftp.openbsd.org/pub/OpenBSD/patches/7.6/common/013_ssh.patch.sig
- https://www.openssh.com/txt/release-7.4
More from OpenBSD
View All →CVE-2025-61985
ssh in OpenSSH before 10.1 allows the '\0' character in...
Low
3.6
CVE-2025-61984
ssh in OpenSSH before 10.1 allows control characters in usernames...
Low
3.6
CVE-2025-30334
OpenBSD wg(4) kernel crash
High
7.1
CVE-2024-11149
OpenBSD vmm GDTR limits
Medium
6.2
CVE-2024-11148
OpenBSD httpd(8) null dereference
High
8.7
Affected Vendor
OpenBSD
View all reports →Affected Software
OpenSSH
Vulnerable Versions:
7.4
Timeline
Official Publish:
April 10th, 2025
Last Modified:
May 8th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.