CVE-2018-7750
Last modified
CVE-2018-7750 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.. EPSS estimates a 27.07% chance of exploitation in the next 30 days.
Description
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Paramiko | Paramiko | < 1.17.6 |
| Paramiko | Paramiko | >= 1.18.0, < 1.18.5 |
| Paramiko | Paramiko | >= 2.0.0, < 2.0.8 |
| Paramiko | Paramiko | >= 2.1.0, < 2.1.5 |
| Paramiko | Paramiko | >= 2.2.0, < 2.2.3 |
| Paramiko | Paramiko | >= 2.3.0, < 2.3.2 |
| Paramiko | Paramiko | 2.4.0 |
| Redhat | Ansible Engine | 2.0 |
| Redhat | Ansible Engine | 2.4 |
| Redhat | Cloudforms | 4.5 |
| Redhat | Cloudforms | 4.6 |
| Redhat | Virtualization | 4.1 |
| Redhat | Enterprise Linux Desktop | 6.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Redhat | Enterprise Linux Server | 7.0 |
| Redhat | Enterprise Linux Server Aus | 6.4 |
| Redhat | Enterprise Linux Server Aus | 6.5 |
| Redhat | Enterprise Linux Server Aus | 6.6 |
| Redhat | Enterprise Linux Server Eus | 6.7 |
| Redhat | Enterprise Linux Server Tus | 6.6 |
| Redhat | Enterprise Linux Workstation | 6.0 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://www.securityfocus.com/bid/103713Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0591Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0646Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1124Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1125Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1213Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1274Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1328Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1525Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1972Third Party Advisory
- https://github.com/paramiko/paramiko/blob/master/sites/www/changelog.rstThird Party Advisory
- https://github.com/paramiko/paramiko/commit/fa29bd8446c8eab237f5187d28787727b4610516Patch, Third Party Advisory
- https://github.com/paramiko/paramiko/issues/1175Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00025.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3603-1/Third Party Advisory
- https://usn.ubuntu.com/3603-2/Third Party Advisory
- https://www.exploit-db.com/exploits/45712/Exploit, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/103713Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:0591Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0646Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1124Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1125Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1213Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1274Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1328Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1525Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1972Third Party Advisory
- https://github.com/paramiko/paramiko/blob/master/sites/www/changelog.rstThird Party Advisory
- https://github.com/paramiko/paramiko/commit/fa29bd8446c8eab237f5187d28787727b4610516Patch, Third Party Advisory
- https://github.com/paramiko/paramiko/issues/1175Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/10/msg00018.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00025.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3603-1/Third Party Advisory
- https://usn.ubuntu.com/3603-2/Third Party Advisory
- https://www.exploit-db.com/exploits/45712/Exploit, Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-7750?
How severe is CVE-2018-7750?
How do I fix CVE-2018-7750?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-7741Eramba e1.0.6.033 has Reflected XSS in the Date Filter via t…
- CVE-2018-7745An issue was discovered in Western Bridge Cobub Razor 0.7.2.…7.5
- CVE-2018-7746An issue was discovered in Western Bridge Cobub Razor 0.7.2.…8.8
- CVE-2018-7747Multiple cross-site scripting (XSS) vulnerabilities in the C…
- CVE-2018-7748report_viewer.do in ServiceNow Release Jakarta Patch 8 and e…
- CVE-2018-7749The SSH server implementation of AsyncSSH before 1.12.1 does…
- CVE-2018-7751The svg_probe function in libavformat/img2dec.c in FFmpeg th…
- CVE-2018-7752GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc…
- CVE-2018-7753An issue was discovered in Bleach 2.1.x before 2.1.3. Attrib…
- CVE-2018-7754The aoedisk_debugfs_show function in drivers/block/aoe/aoebl…
- CVE-2018-7755An issue was discovered in the fd_locked_ioctl function in d…
- CVE-2018-7756RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit)…
Are you affected by CVE-2018-7750?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
