PT-2018-3839 · None+4 · Paramiko+4

Adam Brown

·

Published

2018-03-13

·

Updated

2026-06-13

·

CVE-2018-7750

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Paramiko versions prior to 1.17.6 Paramiko versions 1.18.x prior to 1.18.5 Paramiko versions 2.0.x prior to 2.0.8 Paramiko versions 2.1.x prior to 2.1.5 Paramiko versions 2.2.x prior to 2.2.3 Paramiko versions 2.3.x prior to 2.3.2 Paramiko versions 2.4.x prior to 2.4.1
Description The issue is related to the transport.py component of the Paramiko library, which has weaknesses in its authentication procedure. This allows a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. The vulnerability can be exploited by a customized SSH client that skips the authentication step, as demonstrated by the channel-open request.
Recommendations For Paramiko versions prior to 1.17.6, update to version 1.17.6 or later. For Paramiko versions 1.18.x prior to 1.18.5, update to version 1.18.5 or later. For Paramiko versions 2.0.x prior to 2.0.8, update to version 2.0.8 or later. For Paramiko versions 2.1.x prior to 2.1.5, update to version 2.1.5 or later. For Paramiko versions 2.2.x prior to 2.2.3, update to version 2.2.3 or later. For Paramiko versions 2.3.x prior to 2.3.2, update to version 2.3.2 or later. For Paramiko versions 2.4.x prior to 2.4.1, update to version 2.4.1 or later. As a temporary workaround, consider restricting access to the transport.py component until a patch is available.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06039
CESA-2018_1124
CVE-2018-7750
DLA-1556-1
DLA-2860-1
ELSA-2018-1124
GHSA-232R-66CG-79PX
MGASA-2018-0204
OPENSUSE-SU-2018_0799-1
OPENSUSE-SU-2024:11249-1
OPENSUSE-SU-2026:11025-1
PYSEC-2018-19
RHSA-2018:0591
RHSA-2018:0646
RHSA-2018:1124
RHSA-2018:1125
RHSA-2018:1213
RHSA-2018:1274
RHSA-2018:1328
RHSA-2018:1525
RHSA-2018:1972
RHSA-2018_1124
SUSE-FU-2022:0444-1
SUSE-FU-2022:0445-1
SUSE-SU-2018:0844-1
SUSE-SU-2018:0873-1
SUSE-SU-2018:1850-1
SUSE-SU-2018:1971-1
SUSE-SU-2018:2777-1
SUSE-SU-2018_1971-1
SUSE-SU-2018_2777-1
USN-3603-1
USN-3603-2

Affected Products

Centos
Paramiko
Red Hat
Suse
Ubuntu