openssh: User enumeration via malformed packets in authentication requests
Published Aug 17, 2018
5.9
MEDIUMCVSS 3.1
EPSS 98.63%
Description
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
Affected products
No data.
Configuration 2
- 8.0
- 9.0
Configuration 3
- 6.0
- 7.0
- 6.0
- 7.0
- 6.0
- 7.0
Configuration 4
- 14.04
- 16.04
- 18.04
Configuration 5
- n/a
Configuration 6
- n/a
- n/a
- n/a
- n/a
- ≥ 9.4
- n/a
- n/a
- n/a
- ≥ 7.2
- n/a
- n/a
Configuration 7
- ≥ 7.2
Running on/with
- n/a
Configuration 8
- ≥ 7.2
Running on/with
- n/a
Configuration 9
- 8.8.6
Configuration 10
- < 3.2.7
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
openssh-0:5.3p1-124.el6_10
Fixed · RHSA-2019:0711
Red Hat Enterprise Linux 7
openssh-0:7.4p1-21.el7
Fixed · RHSA-2019:2143
Red Hat Enterprise Linux 5
openssh
Will not fix
Red Hat Enterprise Linux 8
openssh
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | openssh-0:5.3p1-124.el6_10 | Fixed | RHSA-2019:0711 |
| Red Hat Enterprise Linux 7 | openssh-0:7.4p1-21.el7 | Fixed | RHSA-2019:2143 |
| Red Hat Enterprise Linux 5 | openssh | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | openssh | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Product Security has rated this issue as having Low severity. An attacker could use this flaw to determine whether given usernames exist or not on the server, but no further information is disclosed and there is no availability or integrity impact. A future update may address this issue.
Red Hat mitigation
Configuring your firewall to limit the origin and/or rate of incoming ssh connections (using the netfilter xt_recent module) will limit the impact of this attack, as it requires a new TCP connection for each username tested. This configuration also provides some protection against brute-force attacks on SSH passwords or keys. See the following article for more information on limiting access to SSHD: https://access.redhat.com/solutions/8687
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Dec 17, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (40 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 98.63% (0.98631) | 99.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 98.63% (0.98631) | 99.92th | v5 (v2026.06.15) |
| Mar 4, 2026 | 90.36% (0.90356) | 99.59th | v4 (v2025.03.14) |
| Mar 1, 2026 | 91.41% (0.91410) | 99.66th | v4 (v2025.03.14) |
| Feb 4, 2026 | 89.96% (0.89957) | 99.56th | v4 (v2025.03.14) |
| Feb 1, 2026 | 91.11% (0.91112) | 99.64th | v4 (v2025.03.14) |
| Jan 4, 2026 | 89.96% (0.89957) | 99.55th | v4 (v2025.03.14) |
| Jan 1, 2026 | 91.11% (0.91112) | 99.63th | v4 (v2025.03.14) |
| Dec 28, 2025 | 89.96% (0.89957) | 99.55th | v4 (v2025.03.14) |
| Dec 27, 2025 | 92.21% (0.92207) | 99.70th | v4 (v2025.03.14) |
| Dec 4, 2025 | 89.88% (0.89879) | 99.54th | v4 (v2025.03.14) |
| Dec 1, 2025 | 91.05% (0.91054) | 99.62th | v4 (v2025.03.14) |
| Nov 21, 2025 | 89.88% (0.89879) | 99.54th | v4 (v2025.03.14) |
| Nov 18, 2025 | 31.48% (0.31483) | 96.54th | v4 (v2025.03.14) |
| Nov 4, 2025 | 89.88% (0.89879) | 99.54th | v4 (v2025.03.14) |
| Nov 1, 2025 | 91.05% (0.91054) | 99.63th | v4 (v2025.03.14) |
| Oct 28, 2025 | 89.88% (0.89879) | 99.54th | v4 (v2025.03.14) |
| Oct 27, 2025 | 92.17% (0.92167) | 99.69th | v4 (v2025.03.14) |
| Oct 4, 2025 | 90.29% (0.90285) | 99.57th | v4 (v2025.03.14) |
| Oct 1, 2025 | 91.36% (0.91357) | 99.66th | v4 (v2025.03.14) |
| Jul 30, 2025 | 92.47% (0.92468) | 99.72th | v4 (v2025.03.14) |
| Mar 17, 2025 | 90.73% (0.90727) | 99.61th | v4 (v2025.03.14) |
| Dec 12, 2024 | 2.37% (0.02366) | 90.21th | v3 (v2023.03.01) |
| Jun 26, 2024 | 2.37% (0.02366) | 89.90th | v3 (v2023.03.01) |
| Jun 1, 2024 | 2.08% (0.02081) | 89.05th | v3 (v2023.03.01) |
| Apr 5, 2024 | 1.95% (0.01951) | 88.46th | v3 (v2023.03.01) |
| Jan 8, 2024 | 2.36% (0.02358) | 88.68th | v3 (v2023.03.01) |
| Oct 22, 2023 | 3.25% (0.03247) | 90.14th | v3 (v2023.03.01) |
| Oct 4, 2023 | 2.50% (0.02502) | 88.84th | v3 (v2023.03.01) |
| Aug 29, 2023 | 3.06% (0.03059) | 89.71th | v3 (v2023.03.01) |
| Aug 11, 2023 | 2.64% (0.02637) | 88.99th | v3 (v2023.03.01) |
| Jul 27, 2023 | 2.52% (0.02520) | 88.71th | v3 (v2023.03.01) |
| Jul 9, 2023 | 2.73% (0.02735) | 89.08th | v3 (v2023.03.01) |
| Mar 7, 2023 | 2.79% (0.02790) | 89.00th | v3 (v2023.03.01) |
| Mar 6, 2023 | 46.51% (0.46512) | 98.43th | v2 (v2022.01.01) |
| Feb 24, 2023 | 46.51% (0.46512) | 98.43th | v2 (v2022.01.01) |
| Feb 4, 2022 | 36.61% (0.36609) | 97.00th | v2 (v2022.01.01) |
| Feb 3, 2022 | 55.87% (0.55872) | 99.13th | v1 |
| Sep 1, 2021 | 55.87% (0.55872) | 99.73th | v1 |
| Apr 14, 2021 | 55.87% (0.55872) | 0.00th | v1 |
References (22)
- http://www.openwall.com/lists/oss-security/2018/08/15/5 Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/105140 vdb-entryBroken LinkThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041487 vdb-entryBroken LinkPatchThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2019:0711 vendor-advisoryThird Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2143 vendor-advisoryThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-15473 Vendor Advisory
- https://bugs.debian.org/906236 Issue TrackingMailing ListPatchThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1619063 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf PatchThird Party Advisory
- https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0 Patch
- https://lists.debian.org/debian-lts-announce/2018/08/msg00022.html mailing-listMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-15473
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2018-0011 Third Party Advisory
- https://security.gentoo.org/glsa/201810-03 vendor-advisoryThird Party Advisory
- https://security.netapp.com/advisory/ntap-20181101-0001/ Third Party Advisory
- https://usn.ubuntu.com/3809-1/ vendor-advisoryThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2018-15473
- https://www.debian.org/security/2018/dsa-4280 vendor-advisoryThird Party Advisory
- https://www.exploit-db.com/exploits/45210/ exploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45233/ exploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/45939/ exploitThird Party AdvisoryVDB Entry
- https://www.oracle.com/security-alerts/cpujan2020.html PatchThird Party Advisory
Change history (0)
No recorded changes yet.