python-paramiko: Authentication bypass in transport.py
Published Mar 13, 2018
9.3
CRITICALCVSS 4.0
EPSS 27.11%
Description
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.
Affected products
No data.
Configuration 1
- < 1.17.6
- ≥ 1.18.0 · < 1.18.5
- ≥ 2.0.0 · < 2.0.8
- ≥ 2.1.0 · < 2.1.5
- ≥ 2.2.0 · < 2.2.3
- ≥ 2.3.0 · < 2.3.2
- 2.4.0
Configuration 2
- 2.0
- 2.4
- 4.5
- 4.6
- 4.1
- 6.0
- 6.0
- 7.0
- 6.4
- 6.5
- 6.6
- 6.7
- 6.6
- 6.0
Configuration 3
- 8.0
- 9.0
No data.
CloudForms Management Engine 5.8
ansible-0:2.4.4.0-1.el7ae
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
ansible-tower-0:3.1.7-1.el7at
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
cfme-0:5.8.4.5-1.el7cf
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
cfme-appliance-0:5.8.4.5-1.el7cf
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
cfme-gemset-0:5.8.4.5-1.el7cf
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.8
rh-ruby23-rubygem-json-0:2.1.0-1.el7cf
Fixed · RHSA-2018:1972
CloudForms Management Engine 5.9
ansible-0:2.4.4.0-1.el7ae
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
ansible-tower-0:3.2.4-1.el7at
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
cfme-0:5.9.2.4-1.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
cfme-amazon-smartstate-0:5.9.2.4-1.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
cfme-appliance-0:5.9.2.4-1.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
cfme-gemset-0:5.9.2.4-1.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
dbus-api-service-0:1.0.1-3.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
httpd-configmap-generator-0:0.2.1-2.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
postgresql96-0:9.6.6-1PGDG.el7
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
rh-ruby23-rubygem-json-0:2.1.0-1.el7cf
Fixed · RHSA-2018:1328
CloudForms Management Engine 5.9
rh-ruby23-rubygem-qpid_proton-0:0.22.0-2.el7cf
Fixed · RHSA-2018:1328
Red Hat Ansible Engine 2 for RHEL 7
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:0646
Red Hat Ansible Engine 2.4 for RHEL 7
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:1213
Red Hat Enterprise Linux 6
python-paramiko-0:1.7.5-4.el6_9
Fixed · RHSA-2018:1124
Red Hat Enterprise Linux 6.4 Advanced Update Support
python-paramiko-0:1.7.5-4.el6_4
Fixed · RHSA-2018:1125
Red Hat Enterprise Linux 6.5 Advanced Update Support
python-paramiko-0:1.7.5-4.el6_5
Fixed · RHSA-2018:1125
Red Hat Enterprise Linux 6.6 Advanced Update Support
python-paramiko-0:1.7.5-4.el6_6
Fixed · RHSA-2018:1125
Red Hat Enterprise Linux 6.6 Telco Extended Update Support
python-paramiko-0:1.7.5-4.el6_6
Fixed · RHSA-2018:1125
Red Hat Enterprise Linux 6.7 Extended Update Support
python-paramiko-0:1.7.5-4.el6_7
Fixed · RHSA-2018:1125
Red Hat Enterprise Linux 7 Extras
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:0591
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:1274
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7
rhvm-appliance-0:4.2-20180504.0
Fixed · RHSA-2018:1525
Red Hat Virtualization Engine 4.1
python-paramiko-0:2.1.1-4.el7
Fixed · RHSA-2018:1274
Red Hat Ceph Storage 2
python-paramiko
Affected
Red Hat Enterprise Linux OpenStack Platform 7 (Kilo)
python-paramiko
Will not fix
Red Hat OpenShift Enterprise 3
python-paramiko
Affected
Red Hat OpenStack Platform 10 (Newton)
python-paramiko
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
python-paramiko
Will not fix
Red Hat OpenStack Platform 12 (Pike)
python-paramiko
Will not fix
Red Hat OpenStack Platform 13 (Queens)
python-paramiko
Affected
Red Hat OpenStack Platform 8 (Liberty)
python-paramiko
Will not fix
Red Hat OpenStack Platform 9 (Mitaka)
python-paramiko
Will not fix
Red Hat Quickstart Cloud Installer 1
python-paramiko
Will not fix
Red Hat Satellite 6
python-paramiko
Out of support scope
Red Hat Storage 3
python-paramiko
Fix deferred
Red Hat Storage Console 2
python-paramiko
Will not fix
Red Hat Update Infrastructure 3 for Cloud Providers
python-paramiko
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| CloudForms Management Engine 5.8 | ansible-0:2.4.4.0-1.el7ae | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | ansible-tower-0:3.1.7-1.el7at | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | cfme-0:5.8.4.5-1.el7cf | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | cfme-appliance-0:5.8.4.5-1.el7cf | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | cfme-gemset-0:5.8.4.5-1.el7cf | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.8 | rh-ruby23-rubygem-json-0:2.1.0-1.el7cf | Fixed | RHSA-2018:1972 |
| CloudForms Management Engine 5.9 | ansible-0:2.4.4.0-1.el7ae | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | ansible-tower-0:3.2.4-1.el7at | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | cfme-0:5.9.2.4-1.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | cfme-amazon-smartstate-0:5.9.2.4-1.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | cfme-appliance-0:5.9.2.4-1.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | cfme-gemset-0:5.9.2.4-1.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | dbus-api-service-0:1.0.1-3.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | httpd-configmap-generator-0:0.2.1-2.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | postgresql96-0:9.6.6-1PGDG.el7 | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | rh-ruby23-rubygem-json-0:2.1.0-1.el7cf | Fixed | RHSA-2018:1328 |
| CloudForms Management Engine 5.9 | rh-ruby23-rubygem-qpid_proton-0:0.22.0-2.el7cf | Fixed | RHSA-2018:1328 |
| Red Hat Ansible Engine 2 for RHEL 7 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:0646 |
| Red Hat Ansible Engine 2.4 for RHEL 7 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:1213 |
| Red Hat Enterprise Linux 6 | python-paramiko-0:1.7.5-4.el6_9 | Fixed | RHSA-2018:1124 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | python-paramiko-0:1.7.5-4.el6_4 | Fixed | RHSA-2018:1125 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | python-paramiko-0:1.7.5-4.el6_5 | Fixed | RHSA-2018:1125 |
| Red Hat Enterprise Linux 6.6 Advanced Update Support | python-paramiko-0:1.7.5-4.el6_6 | Fixed | RHSA-2018:1125 |
| Red Hat Enterprise Linux 6.6 Telco Extended Update Support | python-paramiko-0:1.7.5-4.el6_6 | Fixed | RHSA-2018:1125 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | python-paramiko-0:1.7.5-4.el6_7 | Fixed | RHSA-2018:1125 |
| Red Hat Enterprise Linux 7 Extras | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:0591 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:1274 |
| Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | rhvm-appliance-0:4.2-20180504.0 | Fixed | RHSA-2018:1525 |
| Red Hat Virtualization Engine 4.1 | python-paramiko-0:2.1.1-4.el7 | Fixed | RHSA-2018:1274 |
| Red Hat Ceph Storage 2 | python-paramiko | Affected | n/a |
| Red Hat Enterprise Linux OpenStack Platform 7 (Kilo) | python-paramiko | Will not fix | n/a |
| Red Hat OpenShift Enterprise 3 | python-paramiko | Affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | python-paramiko | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | python-paramiko | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | python-paramiko | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | python-paramiko | Affected | n/a |
| Red Hat OpenStack Platform 8 (Liberty) | python-paramiko | Will not fix | n/a |
| Red Hat OpenStack Platform 9 (Mitaka) | python-paramiko | Will not fix | n/a |
| Red Hat Quickstart Cloud Installer 1 | python-paramiko | Will not fix | n/a |
| Red Hat Satellite 6 | python-paramiko | Out of support scope | n/a |
| Red Hat Storage 3 | python-paramiko | Fix deferred | n/a |
| Red Hat Storage Console 2 | python-paramiko | Will not fix | n/a |
| Red Hat Update Infrastructure 3 for Cloud Providers | python-paramiko | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw is a user authentication bypass in the SSH Server functionality of paramiko (normally used by subclassing `paramiko.ServerInterface`). Where paramiko is used only for its client-side functionality (e.g. `paramiko.SSHClient`), the vulnerability is not exposed and thus cannot be exploited. The following Red Hat products use paramiko only in client-side mode. Server side functionality is not used. * Red Hat Ceph Storage 2 * Red Hat CloudForms 4 * Red Hat Enterprise Linux 7 * Red Hat Enterprise Virtualization * Red Hat Gluster Storage 3 * Red Hat Openshift Container Platform * Red Hat Quick Cloud Installer * Red Hat Satellite 6 * Red Hat Storage Console 2 * Red Hat OpenStack Platform * Red Hat Update Infrastructure
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (33 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 27.11% (0.27105) | 98.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 27.07% (0.27065) | 97.78th | v5 (v2026.06.15) |
| Jun 9, 2026 | 17.69% (0.17687) | 95.25th | v4 (v2025.03.14) |
| Apr 13, 2026 | 13.83% (0.13825) | 94.29th | v4 (v2025.03.14) |
| Jan 9, 2026 | 20.36% (0.20359) | 95.33th | v4 (v2025.03.14) |
| Nov 21, 2025 | 16.05% (0.16054) | 94.51th | v4 (v2025.03.14) |
| Nov 18, 2025 | 60.34% (0.60335) | 98.24th | v4 (v2025.03.14) |
| Aug 30, 2025 | 16.74% (0.16742) | 94.68th | v4 (v2025.03.14) |
| Aug 29, 2025 | 17.84% (0.17842) | 94.88th | v4 (v2025.03.14) |
| Aug 1, 2025 | 20.89% (0.20890) | 95.43th | v4 (v2025.03.14) |
| Jun 3, 2025 | 22.20% (0.22204) | 95.50th | v4 (v2025.03.14) |
| Apr 19, 2025 | 26.48% (0.26481) | 95.98th | v4 (v2025.03.14) |
| Mar 30, 2025 | 22.20% (0.22204) | 95.32th | v4 (v2025.03.14) |
| Mar 29, 2025 | 44.92% (0.44918) | 96.43th | v4 (v2025.03.14) |
| Mar 28, 2025 | 22.20% (0.22204) | 95.32th | v4 (v2025.03.14) |
| Mar 27, 2025 | 44.92% (0.44918) | 97.14th | v4 (v2025.03.14) |
| Mar 20, 2025 | 22.65% (0.22653) | 95.41th | v4 (v2025.03.14) |
| Mar 19, 2025 | 45.51% (0.45510) | 97.23th | v4 (v2025.03.14) |
| Mar 17, 2025 | 22.65% (0.22653) | 95.40th | v4 (v2025.03.14) |
| Dec 17, 2024 | 3.77% (0.03773) | 91.72th | v3 (v2023.03.01) |
| Jun 16, 2024 | 4.79% (0.04790) | 92.75th | v3 (v2023.03.01) |
| Aug 4, 2023 | 6.63% (0.06627) | 92.83th | v3 (v2023.03.01) |
| Jun 22, 2023 | 5.97% (0.05972) | 92.38th | v3 (v2023.03.01) |
| Apr 30, 2023 | 5.85% (0.05850) | 92.27th | v3 (v2023.03.01) |
| Apr 11, 2023 | 5.56% (0.05560) | 92.04th | v3 (v2023.03.01) |
| Mar 7, 2023 | 4.37% (0.04374) | 91.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 38.05% (0.38053) | 97.95th | v2 (v2022.01.01) |
| Feb 4, 2022 | 38.05% (0.38053) | 97.22th | v2 (v2022.01.01) |
| Feb 3, 2022 | 15.32% (0.15322) | 90.03th | v1 |
| Jan 6, 2022 | 15.32% (0.15322) | 89.91th | v1 |
| Dec 29, 2021 | 15.32% (0.15322) | 97.26th | v1 |
| Sep 1, 2021 | 14.63% (0.14629) | 97.04th | v1 |
| Apr 14, 2021 | 14.63% (0.14629) | 0.00th | v1 |
References (27)
- http://www.securityfocus.com/bid/103713 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:0591 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0646 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1124 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1125 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1213 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1274 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1328 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1525 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/errata/RHSA-2018:1972 vendor-advisoryx_refsource_REDHATThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2018-7750 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1557130 Issue Tracking
- https://github.com/advisories/GHSA-232r-66cg-79px Advisory
- https://github.com/paramiko/paramiko/blob/e861c7697622774071ce73b46ffe8817eacdedfa/sites/www/changelog.rst?plain=1#L759-L763
- https://github.com/paramiko/paramiko/blob/master/sites/www/changelog.rst x_refsource_CONFIRMThird Party Advisory
- https://github.com/paramiko/paramiko/commit/e9dfd854bdaf8af15d7834f7502a0451d217bb8c
- https://github.com/paramiko/paramiko/commit/fa29bd8446c8eab237f5187d28787727b4610516 x_refsource_CONFIRMPatchThird Party Advisory
- https://github.com/paramiko/paramiko/issues/1175 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/paramiko/PYSEC-2018-19.yaml
- https://lists.debian.org/debian-lts-announce/2018/10/msg00018.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/12/msg00025.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-7750
- https://usn.ubuntu.com/3603-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://usn.ubuntu.com/3603-2 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://web.archive.org/web/20190831123128/http://www.securityfocus.com/bid/103713
- https://www.cve.org/CVERecord?id=CVE-2018-7750
- https://www.exploit-db.com/exploits/45712 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
Change history (0)
No recorded changes yet.