CVE-2018-10933

CRITICAL

libssh Authentication Bypass Scanner

Title source: metasploit

Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

Exploits (43)

github WRITEUP 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2018-10933.md
nomisec WORKING POC 498 stars
by blacknbunny · poc
https://github.com/blacknbunny/CVE-2018-10933
nomisec SCANNER 232 stars
by jobroche · poc
https://github.com/jobroche/libssh-scanner
nomisec WORKING POC 126 stars
by SoledaD208 · poc
https://github.com/SoledaD208/CVE-2018-10933
nomisec WORKING POC 109 stars
by hackerhouse-opensource · poc
https://github.com/hackerhouse-opensource/cve-2018-10933
nomisec WORKING POC 21 stars
by jas502n · poc
https://github.com/jas502n/CVE-2018-10933
github WRITEUP 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2018-10933.md
nomisec WORKING POC 14 stars
by kn6869610 · poc
https://github.com/kn6869610/CVE-2018-10933
nomisec WORKING POC 11 stars
by Virgula0 · poc
https://github.com/Virgula0/POC-CVE-2018-10933
nomisec SCANNER 10 stars
by marco-lancini · poc
https://github.com/marco-lancini/hunt-for-cve-2018-10933
nomisec WORKING POC 6 stars
by nikhil1232 · poc
https://github.com/nikhil1232/LibSSH-Authentication-Bypass
nomisec WORKING POC 4 stars
by HSw109 · poc
https://github.com/HSw109/CVE-2018-10933
nomisec WORKING POC 3 stars
by xFreed0m · poc
https://github.com/xFreed0m/CVE-2018-10933
nomisec WORKING POC 2 stars
by shifa123 · poc
https://github.com/shifa123/pythonprojects-CVE-2018-10933
nomisec WORKING POC 1 stars
by Rubikcuv5 · poc
https://github.com/Rubikcuv5/CVE-2018-10933
nomisec SCANNER 1 stars
by ivanacostarubio · poc
https://github.com/ivanacostarubio/libssh-scanner
nomisec WORKING POC 1 stars
by likekabin · poc
https://github.com/likekabin/CVE-2018-10933-libSSH-Authentication-Bypass
nomisec WORKING POC 1 stars
by r3dxpl0it · poc
https://github.com/r3dxpl0it/CVE-2018-10933
nomisec WORKING POC
by likekabin · poc
https://github.com/likekabin/CVE-2018-10933_ssh
nomisec WORKING POC
by SilasSpringer · poc
https://github.com/SilasSpringer/CVE-2018-10933
nomisec WORKING POC
by ninp0 · poc
https://github.com/ninp0/cve-2018-10933_poc
nomisec WORKING POC
by bidaoui4905 · poc
https://github.com/bidaoui4905/CVE-2018-10933
nomisec WORKING POC
by Bifrozt · poc
https://github.com/Bifrozt/CVE-2018-10933
nomisec WORKING POC
by crispy-peppers · poc
https://github.com/crispy-peppers/Libssh-server-CVE-2018-10933
nomisec NO CODE
by lalishasanduwara · poc
https://github.com/lalishasanduwara/CVE-2018-10933
nomisec WRITEUP
by hook-s3c · poc
https://github.com/hook-s3c/CVE-2018-10933
nomisec WORKING POC
by opsifiz · poc
https://github.com/opsifiz/CVE-2018-10933
nomisec SCANNER
by pghook · poc
https://github.com/pghook/CVE-2018-10933_Scanner
nomisec WORKING POC
by cyberharsh · poc
https://github.com/cyberharsh/Libssh-server-CVE-2018-10933
nomisec WORKING POC
by sambiyal · poc
https://github.com/sambiyal/CVE-2018-10933-POC
nomisec WORKING POC
by youkergav · poc
https://github.com/youkergav/CVE-2018-10933
nomisec WRITEUP
by cve-2018 · poc
https://github.com/cve-2018/cve-2018-10933
nomisec WORKING POC
by 0xadaw · poc
https://github.com/0xadaw/libSSH-bypass
nomisec WORKING POC
by ensimag-security · poc
https://github.com/ensimag-security/CVE-2018-10933
nomisec SCANNER
by reanimat0r · poc
https://github.com/reanimat0r/bpnd-libssh
nomisec STUB
by throwawayaccount12312312 · poc
https://github.com/throwawayaccount12312312/precompiled-CVE-2018-10933
nomisec WORKING POC
by Kurlee · poc
https://github.com/Kurlee/LibSSH-exploit
nomisec WORKING POC
by kristyna-mlcakova · poc
https://github.com/kristyna-mlcakova/CVE-2018-10933
nomisec SCANNER
by JoSecMx · poc
https://github.com/JoSecMx/CVE-2018-10933_Scanner
nomisec WORKING POC
by Remnant-DB · poc
https://github.com/Remnant-DB/CVE-2018-10933
exploitdb WORKING POC
by Dayanç Soyadlı · pythonremotelinux
https://www.exploit-db.com/exploits/45638
exploitdb WORKING POC VERIFIED
by jas502n · pythonremotelinux
https://www.exploit-db.com/exploits/46307
metasploit WORKING POC
by Peter Winter-Smith, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ssh/libssh_auth_bypass.rb

Scores

CVSS v3 9.1
EPSS 0.7833
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Classification

CWE
CWE-287 CWE-592
Status published

Affected Products (14)

libssh/libssh < 0.7.6
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux
netapp/oncommand_unified_manager
netapp/oncommand_unified_manager
netapp/oncommand_workflow_automation
netapp/snapcenter
netapp/storage_automation_store
oracle/mysql_workbench < 8.0.13

Timeline

Published Oct 17, 2018
Tracked Since Feb 18, 2026