CVE-2018-10933 is a critical authentication bypass vulnerability in libssh's server-side state machine, affecting versions prior to 0.7.6 and 0.8.4, including products from Canonical, Debian, Oracle, and Red Hat. With a CVSS score of 9.1, it allows unauthenticated remote attackers to create channels and gain unauthorized access with low attack complexity and no user interaction. While not on the KEV catalog, public exploit code is available in Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high likelihood of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.6.0, < 0.7.6CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
>= 0.8.0, < 0.8.4CPE matchmatch criteria | cpe:2.3:a:libssh:libssh:*:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.