CVE-2017-18594 describes a denial-of-service vulnerability affecting Nmap 7.70, specifically within its nse_libssh2.cc component. This flaw, a double free error, occurs when an SSH connection fails, particularly when a leading newline character is used with scripts like ssh-brute.nse or ssh-auth-methods.nse. The vulnerability carries a CVSS v3 score of 7.5 (HIGH), indicating a significant risk. It can be exploited remotely with low attack complexity and no user interaction, leading to a complete denial of service (availability impact). Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.70CPE matchmatch criteria | cpe:2.3:a:nmap:nmap:7.70:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.