Back

CVE-2018-10933

CRITICAL

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Published: Oct 17, 2018 Modified: Jun 17, 2026
CWE-592 CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected Products (15)

Vendor Product Version
libssh libssh * ≥ 0.6.0 < 0.7.6
libssh libssh * ≥ 0.8.0 < 0.8.4
canonical ubuntu_linux 14.04
canonical ubuntu_linux 16.04
canonical ubuntu_linux 18.04
canonical ubuntu_linux 18.10
debian debian_linux 8.0
debian debian_linux 9.0
redhat enterprise_linux 7.0
netapp oncommand_unified_manager * ≥ 7.3
netapp oncommand_unified_manager * ≥ 9.4
netapp oncommand_workflow_automation -
netapp snapcenter -
netapp storage_automation_store -
oracle mysql_workbench *

GitHub Security Advisory GHSA-22gf-f5w4-hrfq

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4....

Risk Scores

CVSS Score 9.1 / 10
EPSS Score 91.79%

Top 0% most likely to be exploited

Threat Score 73.9 / 100

Data Sources

NVD EPSS GitHub