CyberSec.Space Logo
Back to CVE Browser

CVE-2018-10933

CRITICAL
9.1
CVSS Severity Score
EPSS Score0.1790%
EPSS Percentile41.44th
PublishedOct 17, 2018
Last ModifiedNov 21, 2024

Vulnerability Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Affected Platforms (CPE)

πŸ“¦
Libssh

Libssh

>= 0.6.0 and < 0.7.6
πŸ“¦
Libssh

Libssh

>= 0.8.0 and < 0.8.4
πŸ’»
Canonical

Ubuntu Linux

= 14.04
πŸ’»
Canonical

Ubuntu Linux

= 16.04
πŸ’»
Canonical

Ubuntu Linux

= 18.04
πŸ’»
Canonical

Ubuntu Linux

= 18.10
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ’»
Redhat

Enterprise Linux

= 7.0
πŸ“¦
Netapp

Oncommand Unified Manager

>= 7.3
πŸ“¦
Netapp

Oncommand Unified Manager

>= 9.4
πŸ“¦
Netapp

Oncommand Workflow Automation

All versions
πŸ“¦
Netapp

Snapcenter

All versions
πŸ“¦
Netapp

Storage Automation Store

All versions
πŸ“¦
Oracle

Mysql Workbench

<= 8.0.13

References & Advisories

Related Vulnerabilities