Authentication bypass in libssh - CVE-2018-10933
Published: October 17, 2018 / Updated: June 9, 2022
Vulnerability identifier: #VU15379
CSH Severity: Low
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-10933
CWE-ID: CWE-592
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication on the target system.
The weakness exists due to coding error, when libssh receives the "SSH2_MSG_USERAUTH_SUCCESS" message. A remote attacker can send the SSH server "SSH2_MSG_USERAUTH_SUCCESS" message instead of the "SSH2_MSG_USERAUTH_REQUEST" message that a server usually expects and which libssh uses as a sign that an authentication procedure needs to initiate, bypass authentication procedures and gain access to a server with an SSH connection enabled without having to enter the password.
The weakness exists due to coding error, when libssh receives the "SSH2_MSG_USERAUTH_SUCCESS" message. A remote attacker can send the SSH server "SSH2_MSG_USERAUTH_SUCCESS" message instead of the "SSH2_MSG_USERAUTH_REQUEST" message that a server usually expects and which libssh uses as a sign that an authentication procedure needs to initiate, bypass authentication procedures and gain access to a server with an SSH connection enabled without having to enter the password.
Affected software
libssh
Arch Linux
Debian Linux
Slackware Linux
Opensuse
Fedora
libssh (Alpine package)
libssh
IBM Tivoli Storage Manager
MySQL Workbench
FOX615
Arch Linux
Debian Linux
Slackware Linux
Opensuse
Fedora
libssh (Alpine package)
libssh
IBM Tivoli Storage Manager
MySQL Workbench
FOX615
How to mitigate CVE-2018-10933
The vulnerability has been addressed in the version 0.7.4, 0.8.6.
libssh - addressed in versions 0.7.6, 0.8.4
libssh (Alpine package) - update to 0.7.6-r0
MySQL Workbench - update to 8.0.14
FOX615 - addressed in versions cesne_r1h07_12, cesne_r2d14_03
libssh - addressed in versions 0.7.6-1.fc27, 0.8.4-1.fc28, 0.8.4-1.fc29
libssh (Alpine package) - update to 0.7.6-r0
MySQL Workbench - update to 8.0.14
FOX615 - addressed in versions cesne_r1h07_12, cesne_r2d14_03
libssh - addressed in versions 0.7.6-1.fc27, 0.8.4-1.fc28, 0.8.4-1.fc29
Links to Public Exploits and PoC-codes
- Exploit #8006 - learn-exploit-cve (? Learning how to exploit the popular CVE) (June 9, 2022)
- Exploit #2379 - cve-2018-10933_poc (Variant of hackerhouse-opensource/cve-2018-10933) (April 7, 2020)
- Exploit #1978 - LibSSH-exploit (Takes advantage of CVE-2018-10933) (March 18, 2020)
- Exploit #1991 - Alien-Framework (Alien-Framework, it is a framework with many CVE exploits and tools to use in pen-testing.) (March 18, 2020)
- Exploit #2065 - CVE-2018-10933 (a python script to exploit libssh authentication vulnerability) (March 18, 2020)
- Exploit #84 - libssh Authentication Bypass Scanner (March 18, 2020)
- Exploit #212 - CVE-2018-10933 (CVE-2018-10933 sshlib user authentication attack - docker lab, test and exploit) (March 18, 2020)
- Exploit #213 - hunt-for-cve-2018-10933 (Hunt for and Exploit the libSSH Authentication Bypass (CVE-2018-10933)) (March 18, 2020)
- Exploit #214 - POC-CVE-2018-10933 (LibSSH Authentication Bypass Exploit using RCE) (March 18, 2020)
External References
Related Security Bulletins
- Authentication bypass in libssh
- Slackware Linux update for libssh
- Arch Linux update for libssh
- Debian update for libssh
- OpenSUSE Linux update for libssh
- OpenSUSE Linux update for libssh
- Authentication bypass in libssh (Alpine package)
- Hitachi ABB Power Grids FOX615 Multiservice-Multiplexer update for libssh library
- Fedora 29 update for libssh
- Fedora 28 update for libssh
- Fedora 27 update for libssh
- Multiple vulnerabilities in MySQL Workbench