CVE-2018-10933
CRITICAL
9.1
CVSS Severity Score
Vulnerability Description
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Affected Platforms (CPE)
π¦
Libssh
Libssh
>= 0.6.0 and < 0.7.6π¦
Libssh
Libssh
>= 0.8.0 and < 0.8.4π»
Canonical
Ubuntu Linux
= 14.04π»
Canonical
Ubuntu Linux
= 16.04π»
Canonical
Ubuntu Linux
= 18.04π»
Canonical
Ubuntu Linux
= 18.10π»
Debian
Debian Linux
= 8.0π»
Debian
Debian Linux
= 9.0π»
Redhat
Enterprise Linux
= 7.0π¦
Netapp
Oncommand Unified Manager
>= 7.3π¦
Netapp
Oncommand Unified Manager
>= 9.4π¦
Netapp
Oncommand Workflow Automation
All versionsπ¦
Netapp
Snapcenter
All versionsπ¦
Netapp
Storage Automation Store
All versionsπ¦
Oracle
