« List of all CVEs

CVE-2018-10933

Published: 10/17/2018 Last updated: 8/5/2024 Reserved: 5/9/2018

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Metrics

Version Score Severity Vector String
3.0 9.1 Critical CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Opam packages affected (1)

libssh

Products affected (1)

Product Vendor Version
libssh [UNKNOWN] n/a

References (22)