A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
2018-10-17T12:29:00.650
2024-11-21T03:42:20.323
Modified
CVSSv3.0: 9.1 (CRITICAL)
AV:N/AC:L/Au:N/C:P/I:P/A:N
10.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | libssh | libssh | < 0.7.6 | Yes |
Application | libssh | libssh | < 0.8.4 | Yes |
Operating System | canonical | ubuntu_linux | 14.04 | Yes |
Operating System | canonical | ubuntu_linux | 16.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.04 | Yes |
Operating System | canonical | ubuntu_linux | 18.10 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | Yes |
Application | netapp | oncommand_unified_manager | ≥ 7.3 | Yes |
Application | netapp | oncommand_unified_manager | ≥ 9.4 | Yes |
Application | netapp | oncommand_workflow_automation | - | Yes |
Application | netapp | snapcenter | - | Yes |
Application | netapp | storage_automation_store | - | Yes |
Application | oracle | mysql_workbench | ≤ 8.0.13 | Yes |