CVE-2018-10933
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first...
- Published
- Oct 17, 2018
- Updated
- Aug 5, 2024
- Assigning CNA
- redhat
- Evidence observed
- Oct 18, 2018
Primary CVSS
nvd · CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.
Sources
39Implementation of CVE-2018-10933 with CIDR block scanner
- CVE-2018-10933Exploit
Exploit for CVE-2018-10933 (LibSSH authentication bypass) enabling unauthenticated shell access to vulnerable SSH servers with version detection and Shodan integration.
- cve-2018-10933Exploit
Docker-based CVE-2018-10933 libssh authentication bypass exploit with patched client for testing SSH server vulnerabilities and unauthorized access scenarios.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.