CVE-2018-15473

MEDIUM

Openbsd Openssh < 7.7 - Race Condition

Title source: rule

Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

Exploits (50)

nomisec WORKING POC 533 stars
by Rhynorater · poc
https://github.com/Rhynorater/CVE-2018-15473-Exploit
nomisec WORKING POC 156 stars
by trimstray · poc
https://github.com/trimstray/massh-enum
nomisec WORKING POC 111 stars
by epi052 · poc
https://github.com/epi052/cve-2018-15473
nomisec WORKING POC 43 stars
by Sait-Nuri · poc
https://github.com/Sait-Nuri/CVE-2018-15473
nomisec WORKING POC 17 stars
by r3dxpl0it · poc
https://github.com/r3dxpl0it/CVE-2018-15473
nomisec WORKING POC 4 stars
by sergiovks · poc
https://github.com/sergiovks/SSH-User-Enum-Python3-CVE-2018-15473
nomisec WORKING POC 3 stars
by MrDottt · poc
https://github.com/MrDottt/CVE-2018-15473
nomisec WORKING POC 3 stars
by gbonacini · poc
https://github.com/gbonacini/opensshenum
nomisec WORKING POC 2 stars
by JoeBlackSecurity · poc
https://github.com/JoeBlackSecurity/SSHUsernameBruter-SSHUB
nomisec SCANNER 1 stars
by anonymous121029034720384234234 · poc
https://github.com/anonymous121029034720384234234/py-network-scanner
nomisec WORKING POC 1 stars
by 0xrobiul · poc
https://github.com/0xrobiul/CVE-2018-15473
nomisec STUB 1 stars
by mclbn · poc
https://github.com/mclbn/docker-cve-2018-15473
nomisec STUB 1 stars
by cved-sources · poc
https://github.com/cved-sources/cve-2018-15473
gitlab WORKING POC 1 stars
by epi052 · poc
https://gitlab.com/epi052/cve-2018-15473
nomisec WORKING POC 1 stars
by OmarV4066 · poc
https://github.com/OmarV4066/SSHEnumKL
nomisec WORKING POC 1 stars
by NHPT · poc
https://github.com/NHPT/SSH-account-enumeration-verification-script
nomisec WORKING POC 1 stars
by LINYIKAI · poc
https://github.com/LINYIKAI/CVE-2018-15473-exp
nomisec WORKING POC
by coollce · poc
https://github.com/coollce/CVE-2018-15473_burte
nomisec WORKING POC
by philippedixon · poc
https://github.com/philippedixon/CVE-2018-15473
nomisec WORKING POC
by MahdiOsman · poc
https://github.com/MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
nomisec SCANNER
by Moon1705 · poc
https://github.com/Moon1705/easy_security
nomisec STUB
by 4xolotl · poc
https://github.com/4xolotl/CVE-2018-15473
nomisec WORKING POC
by WildfootW · poc
https://github.com/WildfootW/CVE-2018-15473_OpenSSH_7.7
nomisec WORKING POC
by 66quentin · poc
https://github.com/66quentin/shodan-CVE-2018-15473
nomisec SCANNER
by An0nYm0u5101 · poc
https://github.com/An0nYm0u5101/enumpossible
nomisec WORKING POC
by jubeenshah · poc
https://github.com/jubeenshah/CVE-2018-15473-Exploit
gitlab WORKING POC
by xer0dayz · poc
https://gitlab.com/xer0dayz/CVE-2018-15473-Exploit
gitlab WORKING POC
by gavz · poc
https://gitlab.com/gavz/CVE-2018-15473-Exploit
nomisec WORKING POC
by trickster1103 · poc
https://github.com/trickster1103/-
nomisec WORKING POC
by makmour · poc
https://github.com/makmour/open-ssh-user-enumeration
nomisec WORKING POC
by Dirty-Racoon · poc
https://github.com/Dirty-Racoon/CVE-2018-15473-py3
github WORKING POC
by cowsecurity · pythonpoc
https://github.com/cowsecurity/CVE-Exploits/tree/main/CVE-2018-15473
nomisec WORKING POC
by Remnant-DB · poc
https://github.com/Remnant-DB/CVE-2018-15473
nomisec WORKING POC
by pyperanger · poc
https://github.com/pyperanger/CVE-2018-15473_exploit
nomisec WORKING POC
by CaioCGH · poc
https://github.com/CaioCGH/EP4-redes
nomisec WORKING POC
by Wh1t3Fox · poc
https://github.com/Wh1t3Fox/cve-2018-15473
nomisec WORKING POC
by 1stPeak · poc
https://github.com/1stPeak/CVE-2018-15473
nomisec WORKING POC
by SUDORM0X · poc
https://github.com/SUDORM0X/PoC-CVE-2018-15473
nomisec WORKING POC
by 0xNehru · poc
https://github.com/0xNehru/ssh_Enum_vaild
nomisec WORKING POC
by moften · poc
https://github.com/moften/cve-2018-15473-poc
nomisec SCANNER
by Alph4Sec · poc
https://github.com/Alph4Sec/ssh_enum_py
nomisec WORKING POC
by Anonimo501 · poc
https://github.com/Anonimo501/ssh_enum_users_CVE-2018-15473
nomisec WORKING POC
by GaboLC98 · poc
https://github.com/GaboLC98/userenum-CVE-2018-15473
nomisec WORKING POC
by NestyF · poc
https://github.com/NestyF/SSH_Enum_CVE-2018-15473
nomisec WORKING POC
by yZee00 · poc
https://github.com/yZee00/CVE-2018-15473
metasploit WORKING POC
by kenkeiras, Dariusz Tytko, Michal Sajdak, Qualys, wvu · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/ssh/ssh_enumusers.rb
exploitdb WORKING POC VERIFIED
by Justin Gardner · pythonremotelinux
https://www.exploit-db.com/exploits/45233
exploitdb SCANNER VERIFIED
by Matthew Daley · pythonremotelinux
https://www.exploit-db.com/exploits/45210
exploitdb WORKING POC
by Leap Security · pythonremotelinux
https://www.exploit-db.com/exploits/45939

References (18)

Scores

CVSS v3 5.3
EPSS 0.9036
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Classification

CWE
CWE-362
Status published

Affected Products (28)

openbsd/openssh < 7.7
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux_desktop
redhat/enterprise_linux_desktop
redhat/enterprise_linux_server
redhat/enterprise_linux_server
redhat/enterprise_linux_workstation
redhat/enterprise_linux_workstation
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
netapp/cn1610_firmware
netapp/aff_baseboard_management_controller
netapp/cloud_backup
... and 13 more

Timeline

Published Aug 17, 2018
Tracked Since Feb 18, 2026