cbcvebase.
CVE-2018-10933
published 2018-10-17

CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first…

critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EXPLOIT
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibssh< libssh 0.8.4-1 (bookworm)libssh 0.8.4-1 (bookworm)
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0.6.0 < 0.7.60.7.6
libsshlibssh>= 0.8.0 < 0.8.40.8.4
netapponcommand_unified_manager>= 7.3
netapponcommand_unified_manager>= 9.4
oraclemysql_workbench<= 8.0.13
redhatenterprise_linux

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
osv9.1CRITICAL