Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2018-10933DEPRECATED: Authentication Bypass Issues in Libssh

Severity
9.1CRITICALNVD
EPSS
78.3%
top 0.97%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedOct 17
Latest updateMay 13

Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages4 packages

NVDlibssh/libssh0.6.00.7.6+1
Debianlibssh/libssh< 0.8.4-1+3

Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 14.04, 16.04, 18.04, 18.10, Enterprise Linux 7.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-22gf-f5w4-hrfq: A vulnerability was found in libssh's server-side state machine before versions 02022-05-13
CVEList
CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 02018-10-17
OSV
CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 02018-10-17

💥Exploits & PoCs

2
Exploit-DB
LibSSH 0.7.6 / 0.8.4 - Unauthorized Access2018-10-20
Exploit-DB
libSSH - Authentication Bypass2018-10-18

🔍Detection Rules

1
Suricata
ET INFO Potentially Vulnerable LibSSH Server Observed - Possible Authentication Bypass (CVE-2018-10933)2018-10-19

📋Vendor Advisories

5
Ubuntu
libssh vulnerability2018-10-22
Cisco
libssh Authentication Bypass Vulnerability Affecting Cisco Products: October 20182018-10-19
Ubuntu
libssh vulnerability2018-10-17
Red Hat
libssh: Authentication Bypass due to improper message callbacks implementation2018-10-16
Debian
CVE-2018-10933: libssh - A vulnerability was found in libssh's server-side state machine before versions ...2018

🕵️Threat Intelligence

1
Tenable
libssh Vulnerable to Authentication Bypass (CVE-2018-10933)2018-10-17

💬Community

2
Bugzilla
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation [fedora-all]2018-10-16
Bugzilla
CVE-2018-10933 libssh: Authentication Bypass due to improper message callbacks implementation2018-08-10
CVE-2018-10933 — Libssh vulnerability | cvebase