Authentication bypass in Paramiko - CVE-2018-7750
Published: March 16, 2018 / Updated: June 17, 2021
Vulnerability identifier: #VU11130
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-7750
CWE-ID: CWE-592
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote unauthenticated attacker to bypass authentication.
The weakness exists is due to improper security restrictions. A remote attacker can use a customized SSH client, bypass authentication and gain unauthorized access to resources on the target systemю
The weakness exists is due to improper security restrictions. A remote attacker can use a customized SSH client, bypass authentication and gain unauthorized access to resources on the target systemю
Affected software
Paramiko
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Ansible Engine
py3-paramiko (Alpine package)
python-paramiko
Red Hat Virtualization Host
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization Manager
CloudForms
IBM Netezza Analytics
Amazon Linux AMI
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux for Power
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Fedora
Red Hat Enterprise Linux for x86_64
Red Hat Ansible Engine
py3-paramiko (Alpine package)
python-paramiko
Red Hat Virtualization Host
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Virtualization Manager
CloudForms
IBM Netezza Analytics
How to mitigate CVE-2018-7750
Update to versions 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5 or 1.17.6.
py3-paramiko (Alpine package) - update to 2.6.0-r0
python-paramiko - addressed in versions 2.1.1-0.4.el7, 2.2.3-1.fc26, 2.3.2-1.fc27, 2.4.1-1.fc28
IBM Netezza Analytics - update to 11.2.29
python-paramiko - addressed in versions 2.1.1-0.4.el7, 2.2.3-1.fc26, 2.3.2-1.fc27, 2.4.1-1.fc28
IBM Netezza Analytics - update to 11.2.29
Links to Public Exploits and PoC-codes
External References
Related Security Bulletins
- Authentication bypass in Paramiko
- OpenSUSE Linux update for python-paramiko
- Red Hat update for Paramiko
- SUSE Linux update for python-paramiko
- SUSE Linux update for python-paramiko
- Amazon Linux AMI update for python-paramiko
- Red Hat update for python-paramiko
- Red Hat update for python-paramiko
- Red Hat update for Paramiko
- Red Hat update for Paramiko
- Red Hat update for jackson-databind
- Red Hat update for cloudforms
- Multiple vulnerabilities in Red Hat CloudForms
- Authentication bypass in py3-paramiko (Alpine package)
- Fedora 28 update for python-paramiko
- Fedora 26 update for python-paramiko
- Fedora 27 update for python-paramiko
- Fedora EPEL 7 update for python-paramiko
- Multiple vulnerabilities in IBM Netezza Analytics - NPS