Sploitus

CVE-2018-7750

11 known exploits for CVE-2018-7750

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Affected products
Centos, Paramiko, Red Hat, Suse, Ubuntu
Paramiko
< 1.17.6, 1.18.5, 2.0.8, 2.1.5, 2.2.3, 2.3.2, 2.4.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
27.1% (98th percentile)
Weakness
CWE-287
NVD status
Modified
Published
2018-03-13
CVE-2018-7750 at NVD
Authoritative description, scoring and affected products

11 known exploits for CVE-2018-7750

Proof-of-concept code and exploit modules indexed by Sploitus