CVE-2018-7750
Description
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
20.05
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 1.17.6 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 1.18.5 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 2.0.8 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 2.1.5 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 2.2.3 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 2.3.2 | Windows |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko 2.4.1 | Windows |
| Python SSH2 library (USN-3603-1) python-paramiko_2.0.0-1ubuntu0.1_all.deb | Linux |
| Python SSH2 library (USN-3603-1) python-paramiko_1.16.0-1ubuntu0.1_all.deb | Linux |
| Python SSH2 library (USN-3603-1) python-paramiko_1.10.1-1git1ubuntu0.1_all.deb | Linux |
| Python SSH2 library (USN-3603-1) python3-paramiko_2.0.0-1ubuntu0.1_all.deb | Linux |
| Python SSH2 library (USN-3603-1) python3-paramiko_1.16.0-1ubuntu0.1_all.deb | Linux |
| (RHSA-2018:0591) Critical: python-paramiko security and bug fix update python-paramiko-2.1.1-4.el7.noarch.rpm | Linux |
| (RHSA-2018:0591) Critical: python-paramiko security and bug fix update python-paramiko-doc-2.1.1-4.el7.noarch.rpm | Linux |
| (RHSA-2018:1124) Critical: python-paramiko security update python-paramiko-1.7.5-4.el6_9.noarch.rpm | Linux |
| (RHSA-2018:1125) Critical: python-paramiko security update python-paramiko-1.7.5-4.el6_4.noarch.rpm | Linux |
| (RHSA-2018:1125) Critical: python-paramiko security update python-paramiko-1.7.5-4.el6_5.noarch.rpm | Linux |
| (RHSA-2018:1125) Critical: python-paramiko security update python-paramiko-1.7.5-4.el6_6.noarch.rpm | Linux |
| (RHSA-2018:1125) Critical: python-paramiko security update python-paramiko-1.7.5-4.el6_7.noarch.rpm | Linux |
| Python-paramiko update (ELSA-2018-1124) python-paramiko-1.7.5-4.el6_9.noarch.rpm | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 1.17.6 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 1.18.5 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 2.0.8 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 2.1.5 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 2.2.3 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 2.3.2 | Linux |
| Vulnerabilities CVE-2018-7750 are fixed in Python-paramiko for linux 2.4.1 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234