ZeroHour

CVE-2018-10933

PoC
CVSS 3.0
9.1 critical
EPSS
92%p100
Published
()
Modified
Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Vendors
libsshcanonicaldebianredhatnetapporacle
Products
libssh, ubuntu linux, debian linux, enterprise linux, oncommand unified manager, oncommand workflow automation, snapcenter, storage automation store, mysql workbench
Weakness
CWE-592, CWE-287
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news