CVE-2018-15473
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Affected (27)
Products: Openbsd: Openssh · Debian: Debian Linux · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · +4 more
Show all products
Openbsd: Openssh · Debian: Debian Linux · Redhat: Enterprise Linux Desktop, Enterprise Linux Server, Enterprise Linux Workstation · Canonical: Ubuntu Linux · Netapp: Cn1610 Firmware, Aff Baseboard Management Controller, Cloud Backup, Data Ontap, Data Ontap Edge, Fas Baseboard Management Controller, Oncommand Unified Manager, Ontap Select Deploy, Service Processor, Steelstore Cloud Integrated Storage, Virtual Storage Console, Vasa Provider, Storage Replication Adapter · Oracle: Sun Zfs Storage Appliance Kit · Siemens: Scalance X204rna Firmware
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.0 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 | |
| Version 6.0 | |
| Version 6.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.04 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Netapp Cn1610 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| From 9.4 | |
| All versions | |
| All versions | |
| All versions | |
| From 7.2 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| From 7.2 |
| Running on/with | Platform Versions |
|---|---|
Netapp Clustered Data Ontap | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 8.8.6 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.2.7 |
| Running on/with | Platform Versions |
|---|---|
Siemens Scalance X204rna | All versions |
References (36)
Source: cve@mitre.org
Mailing ListPatchThird Party Advisory
Source: cve@mitre.org
Broken LinkThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Broken LinkPatchThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Issue TrackingMailing ListPatchThird Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: cve@mitre.org
Patch
Source: cve@mitre.org
Mailing ListThird Party Advisory
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing ListPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.