CVE-2018-7750

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:*:*:*:*:*:*:*:*
cpe:2.3:a:paramiko:paramiko:2.4.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:ansible_engine:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ansible_engine:2.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.5:*:*:*:*:*:*:*
cpe:2.3:a:redhat:cloudforms:4.6:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.1:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.4:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_aus:6.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_eus:6.7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_server_tus:6.6:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux_workstation:6.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-13 18:29

Updated : 2024-02-28 16:25


NVD link : CVE-2018-7750

Mitre link : CVE-2018-7750

CVE.ORG link : CVE-2018-7750


JSON object : View

Products Affected

redhat

  • ansible_engine
  • enterprise_linux_desktop
  • enterprise_linux_server_tus
  • enterprise_linux_server_eus
  • enterprise_linux_server
  • enterprise_linux_server_aus
  • enterprise_linux_workstation
  • virtualization
  • cloudforms

debian

  • debian_linux

paramiko

  • paramiko
CWE
CWE-287

Improper Authentication