Lucene search

K
cveMitreCVE-2018-15919
HistoryAug 28, 2018 - 8:29 a.m.

CVE-2018-15919

2018-08-2808:29:00
CWE-200
mitre
web.nvd.nist.gov
12083
In Wild
2
cve-2018-15919
openssh
auth-gss2
remote attack
user enumeration
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.003

Percentile

65.9%

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states ‘We understand that the OpenSSH developers do not want to treat such a username enumeration (or “oracle”) as a vulnerability.’

Affected configurations

Nvd
Node
openbsdopensshRange5.97.8
Node
netappcloud_backupMatch-
OR
netappdata_ontap_edgeMatch-
OR
netappontap_select_deployMatch-
OR
netappsteelstoreMatch-
Node
netappcn1610Match-
AND
netappcn1610_firmwareMatch-
VendorProductVersionCPE
openbsdopenssh*cpe:2.3:a:openbsd:openssh:*:*:*:*:*:*:*:*
netappcloud_backup-cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
netappdata_ontap_edge-cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:*
netappontap_select_deploy-cpe:2.3:a:netapp:ontap_select_deploy:-:*:*:*:*:*:*:*
netappsteelstore-cpe:2.3:a:netapp:steelstore:-:*:*:*:*:*:*:*
netappcn1610-cpe:2.3:h:netapp:cn1610:-:*:*:*:*:*:*:*
netappcn1610_firmware-cpe:2.3:o:netapp:cn1610_firmware:-:*:*:*:*:*:*:*

Social References

More

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.003

Percentile

65.9%