CVE Vulnerabilities

CVE-2018-7750

Improper Authentication

Published: Mar 13, 2018 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
9.8 CRITICAL
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
HIGH
root.io logo minimus.io logo echo.ai logo

transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
ParamikoParamiko*1.17.6 (excluding)
ParamikoParamiko1.18.0 (including)1.18.5 (excluding)
ParamikoParamiko2.0.0 (including)2.0.8 (excluding)
ParamikoParamiko2.1.0 (including)2.1.5 (excluding)
ParamikoParamiko2.2.0 (including)2.2.3 (excluding)
ParamikoParamiko2.3.0 (including)2.3.2 (excluding)
ParamikoParamiko2.4.0 (including)2.4.0 (including)
CloudForms Management Engine 5.8RedHatansible-0:2.4.4.0-1.el7ae*
CloudForms Management Engine 5.8RedHatansible-tower-0:3.1.7-1.el7at*
CloudForms Management Engine 5.8RedHatcfme-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatcfme-appliance-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatcfme-gemset-0:5.8.4.5-1.el7cf*
CloudForms Management Engine 5.8RedHatpython-paramiko-0:2.1.1-4.el7*
CloudForms Management Engine 5.8RedHatrh-ruby23-rubygem-json-0:2.1.0-1.el7cf*
CloudForms Management Engine 5.9RedHatansible-0:2.4.4.0-1.el7ae*
CloudForms Management Engine 5.9RedHatansible-tower-0:3.2.4-1.el7at*
CloudForms Management Engine 5.9RedHatcfme-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-amazon-smartstate-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-appliance-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatcfme-gemset-0:5.9.2.4-1.el7cf*
CloudForms Management Engine 5.9RedHatdbus-api-service-0:1.0.1-3.el7cf*
CloudForms Management Engine 5.9RedHathttpd-configmap-generator-0:0.2.1-2.el7cf*
CloudForms Management Engine 5.9RedHatpostgresql96-0:9.6.6-1PGDG.el7*
CloudForms Management Engine 5.9RedHatpython-paramiko-0:2.1.1-4.el7*
CloudForms Management Engine 5.9RedHatrh-ruby23-rubygem-json-0:2.1.0-1.el7cf*
CloudForms Management Engine 5.9RedHatrh-ruby23-rubygem-qpid_proton-0:0.22.0-2.el7cf*
Red Hat Ansible Engine 2.4 for RHEL 7RedHatpython-paramiko-0:2.1.1-4.el7*
Red Hat Ansible Engine 2 for RHEL 7RedHatpython-paramiko-0:2.1.1-4.el7*
Red Hat Enterprise Linux 6RedHatpython-paramiko-0:1.7.5-4.el6_9*
Red Hat Enterprise Linux 6.4 Advanced Update SupportRedHatpython-paramiko-0:1.7.5-4.el6_4*
Red Hat Enterprise Linux 6.5 Advanced Update SupportRedHatpython-paramiko-0:1.7.5-4.el6_5*
Red Hat Enterprise Linux 6.6 Advanced Update SupportRedHatpython-paramiko-0:1.7.5-4.el6_6*
Red Hat Enterprise Linux 6.6 Telco Extended Update SupportRedHatpython-paramiko-0:1.7.5-4.el6_6*
Red Hat Enterprise Linux 6.7 Extended Update SupportRedHatpython-paramiko-0:1.7.5-4.el6_7*
Red Hat Enterprise Linux 7 ExtrasRedHatpython-paramiko-0:2.1.1-4.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatpython-paramiko-0:2.1.1-4.el7*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7RedHatrhvm-appliance-0:4.2-20180504.0*
Red Hat Virtualization Engine 4.1RedHatpython-paramiko-0:2.1.1-4.el7*
ParamikoUbuntuartful*
ParamikoUbuntudevel*
ParamikoUbuntuesm-infra-legacy/trusty*
ParamikoUbuntuesm-infra/xenial*
ParamikoUbuntutrusty*
ParamikoUbuntutrusty/esm*
ParamikoUbuntuxenial*

Potential Mitigations

References