MEDIUM · 5.3

CVE-2018-15473

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, rel...

Vulnerability Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpenbsdOpenssh<= 7.7
DebianDebian Linux8.0
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Workstation6.0
CanonicalUbuntu Linux14.04
NetappCn1610 Firmware-
NetappCn1610-
NetappAff Baseboard Management Controller-
NetappCloud Backup-
NetappData Ontap Edge-
NetappFas Baseboard Management Controller-
NetappOncommand Unified Manager>= 9.4
NetappOntap Select Deploy-
NetappService Processor-
NetappSteelstore Cloud Integrated Storage-
NetappVirtual Storage Console>= 7.2
NetappClustered Data Ontap-
NetappData Ontap-
NetappVasa Provider>= 7.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-15473?

CVE-2018-15473 is a vulnerability with a CVSS score of 5.3 (MEDIUM). OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, rel...

How severe is CVE-2018-15473?

CVE-2018-15473 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-15473?

Check the references section above for vendor advisories and patch information. Affected products include: Openbsd Openssh, Debian Debian Linux, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Server, Redhat Enterprise Linux Workstation.