cbcvebase.
CVE-2018-10933
published 2018-10-17

CVE-2018-10933: A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first…

PriorityP183critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EXPLOIT
EPSS
91.79%
99.8th percentile
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Affected

17 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlibssh< libssh 0.8.4-1 (bookworm)libssh 0.8.4-1 (bookworm)
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0 < 0.8.4-10.8.4-1
libsshlibssh>= 0.6.0 < 0.7.60.7.6
libsshlibssh>= 0.8.0 < 0.8.40.8.4
netapponcommand_unified_manager>= 7.3
netapponcommand_unified_manager>= 9.4
oraclemysql_workbench<= 8.0.13
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

otherparamiko.common.cMSG_USERAUTH_SUCCESS byte sent before authentication
  • Vulnerable targets must be running libssh in server mode (not client mode); scope detection and patching efforts to server-mode deployments of libssh versions 0.6.0–0.7.5 and 0.8.0–0.8.3.
  • The Metasploit auxiliary module scanner/ssh/libssh_auth_bypass can be used to confirm exploitability; successful exploitation results in an authenticated shell session without credentials being provided.
  • The exploit technique involves sending a response message (normally server→client) back to the server — monitor for role-reversed SSH message flows as a detection signal.
  • ·Only libssh deployments operating in server mode are vulnerable; client-mode libssh is not affected, which significantly limits the exploitable attack surface.
  • ·Metasploit module success is not guaranteed even against vulnerable hosts — the server must trigger the correct shell/exec callbacks after the state machine's authenticated state is set.

CVSS provenance

nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
osv9.1CRITICAL
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.