9.1

CVE-2018-10933

Exploit
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Libssh ≫ Libssh Version >= 0.6.0 < 0.7.6
Libssh ≫ Libssh Version >= 0.8.0 < 0.8.4
Canonical ≫ Ubuntu Linux Version 14.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 16.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.04 SwEdition lts
Canonical ≫ Ubuntu Linux Version 18.10
Debian ≫ Debian Linux Version 8.0
Debian ≫ Debian Linux Version 9.0
Redhat ≫ Enterprise Linux Version 7.0
Netapp ≫ Oncommand Unified Manager SwPlatform windows Version >= 7.3
Netapp ≫ Oncommand Unified Manager SwPlatform vsphere Version >= 9.4
Netapp ≫ Snapcenter Version -
Oracle ≫ Mysql Workbench Version <= 8.0.13
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 91.79% 0.998
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
RedHat 9.1 3.9 5.2
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

CWE-592 DEPRECATED: Authentication Bypass Issues

This weakness has been deprecated because it covered redundant concepts already described in CWE-287.

https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
Patch
Third Party Advisory
https://security.netapp.com/advisory/ntap-20190118-0002/
Third Party Advisory
http://www.securityfocus.com/bid/105677
Third Party Advisory
VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10933
Third Party Advisory
Issue Tracking
https://lists.debian.org/debian-lts-announce/2018/10/msg00010.html
Third Party Advisory
Mailing List
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0016
Third Party Advisory
https://usn.ubuntu.com/3795-1/
Third Party Advisory
https://usn.ubuntu.com/3795-2/
Third Party Advisory
https://www.debian.org/security/2018/dsa-4322
Third Party Advisory
https://www.exploit-db.com/exploits/45638/
Third Party Advisory
Exploit
VDB Entry
https://www.libssh.org/security/advisories/CVE-2018-10933.txt
Vendor Advisory