Security Advisory

CVE-2018-10933

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-10-17 12:00:00
Last updated 2024-08-05 07:54:35
Assigner redhat
CVSS score 9.1
State PUBLISHED

Description

A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.