60
CVE-2018-15473
PoC ×3—CVSS 3.1
5.3 medium
EPSS
99%p100
Published
()
Modified
Description
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
- Vendors
- openbsddebianredhatcanonicalnetapporaclesiemens
- Products
- openssh, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, ubuntu linux, cn1610 firmware, aff baseboard management controller, cloud backup, data ontap edge, fas baseboard management controller, oncommand unified manager
- Weakness
- CWE-362
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N