peter bassill · operator
$ cve CVE-2018-7750 JSON

CVE-2018-7750 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 27.1% (pctl 98)

Patch early

A public exploit exists.

Description

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS27.11% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploityes
Published2018-03-13
Last modified2026-06-17

Affected (11)

VendorProduct
debiandebian linux
paramikoparamiko
redhatansible engine
redhatcloudforms
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation
redhatvirtualization

Public exploits

SourceTitleDate
exploit-dbParamiko 2.4.1 - Authentication Bypass2018-10-29

References

→ the Explorer  ·  watch your stack  ·  NVD