cbcvebase.
CVE-2018-1000805
published 2018-10-08

CVE-2018-1000805: Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This…

high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity.

Affected

40 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianparamiko< paramiko 2.4.2-0.1 (bookworm)paramiko 2.4.2-0.1 (bookworm)
paramikoparamiko
paramikoparamiko
paramikoparamiko
paramikoparamiko
paramikoparamiko
paramikoparamiko
paramikoparamiko
paramikoparamiko>= 0 < 2.4.2-0.12.4.2-0.1
paramikoparamiko>= 0 < 2.4.2-0.12.4.2-0.1
paramikoparamiko>= 0 < 2.4.2-0.12.4.2-0.1
paramikoparamiko>= 0 < 2.4.2-0.12.4.2-0.1
paramikoparamiko>= 1.5.1 < 2.0.92.0.9
paramikoparamiko>= 2.1.0 < 2.1.62.1.6
paramikoparamiko>= 2.2.0 < 2.2.42.2.4
paramikoparamiko>= 2.3.0 < 2.3.32.3.3
paramikoparamiko>= 2.4.0 < 2.4.22.4.2
redhatansible_tower

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH