7.5
CVSSv2

CVE-2018-7749

Published: 12/03/2018 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The SSH server implementation of AsyncSSH prior to 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.

Vulnerable Product Search on Vulmon Subscribe to Product

asyncssh project asyncssh

Vendor Advisories

Debian Bug report logs - #892787 python-asyncssh: CVE-2018-7749 Package: src:python-asyncssh; Maintainer for src:python-asyncssh is Debian Python Modules Team <python-modules-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 12 Mar 2018 21:21:02 UTC Severity: grave Tags: ...