cbcvebase.
CVE-2018-15473
published 2018-08-17

CVE-2018-15473: OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet…

medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EXPLOIT
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

Affected

34 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debiandropbear< dropbear 2018.76-4 (bookworm)dropbear 2018.76-4 (bookworm)
debianopenssh< openssh 1:7.7p1-4 (bookworm)openssh 1:7.7p1-4 (bookworm)
dropbear_ssh_projectdropbear_ssh<= 2018.76
dropbear_ssh_projectdropbear_ssh>= 0 < 2018.76-42018.76-4
dropbear_ssh_projectdropbear_ssh>= 0 < 2018.76-42018.76-4
dropbear_ssh_projectdropbear_ssh>= 0 < 2018.76-42018.76-4
dropbear_ssh_projectdropbear_ssh>= 0 < 2018.76-42018.76-4
netapponcommand_unified_manager>= 9.4
netappstorage_replication_adapter>= 7.2
netappvasa_provider>= 7.2
netappvirtual_storage_console>= 7.2
openbsdopenssh<= 7.7
openbsdopenssh>= 0 < 1:7.7p1-41:7.7p1-4
openbsdopenssh>= 0 < 1:7.7p1-41:7.7p1-4
openbsdopenssh>= 0 < 1:7.7p1-41:7.7p1-4
openbsdopenssh>= 0 < 1:7.7p1-41:7.7p1-4
openbsdopenssh>= 0 < 1:6.6p1-2ubuntu2.111:6.6p1-2ubuntu2.11
openbsdopenssh>= 0 < 1:7.2p2-4ubuntu2.61:7.2p2-4ubuntu2.6
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.11:7.6p1-4ubuntu0.1
openbsdopenssh>= 0 < 1:7.6p1-4ubuntu0.51:7.6p1-4ubuntu0.5

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
osv7.5HIGH