ZeroHour

CVE-2018-15473

PoC ×3
CVSS 3.1
5.3 medium
EPSS
99%p100
Published
()
Modified
Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

Vendors
openbsddebianredhatcanonicalnetapporaclesiemens
Products
openssh, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, ubuntu linux, cn1610 firmware, aff baseboard management controller, cloud backup, data ontap edge, fas baseboard management controller, oncommand unified manager
Weakness
CWE-362
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news