CVE-2018-15473
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- August 17, 2018
- Published Date
- August 17, 2018
- Last Updated
- December 17, 2025
- Vendor
- n/a
- Product
- n/a
- Description
- OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v2.0
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
SSVC Information
- Exploitation
- poc
- Technical Impact
- partial
Exploit Status
- Proof of Concept Available
- Yes (added 2018-08-21 00:09:56 UTC) Source
References
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| The Shadowserver (via CIRCL) | 2026-04-15 14:28:36 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
SUDORM0X/PoC-CVE-2018-15473
Type: github • Created: 2024-11-20 13:40:14 UTC • Stars: 0
MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing
Type: github • Created: 2024-08-15 11:37:09 UTC • Stars: 0
yZeetje/CVE-2018-15473
Type: github • Created: 2024-06-13 09:55:01 UTC • Stars: 0
NestyF/SSH_Enum_CVE-2018-15473
Type: github • Created: 2023-11-02 16:30:52 UTC • Stars: 0
4xolotl/CVE-2018-15473
Type: github • Created: 2023-10-31 11:23:34 UTC • Stars: 0
GaboLC98/userenum-CVE-2018-15473
Type: github • Created: 2023-05-05 21:23:29 UTC • Stars: 0
Anonimo501/ssh_enum_users_CVE-2018-15473
Type: github • Created: 2023-04-21 13:16:29 UTC • Stars: 0
sergiovks/SSH-User-Enum-Python3-CVE-2018-15473
Type: github • Created: 2023-03-09 15:23:53 UTC • Stars: 4
philippedixon/CVE-2018-15473
Type: github • Created: 2023-01-01 19:31:24 UTC • Stars: 0
0xrobiul/CVE-2018-15473
Type: github • Created: 2022-09-03 11:44:12 UTC • Stars: 1
66quentin/shodan-CVE-2018-15473
Type: github • Created: 2021-12-11 15:50:57 UTC • Stars: 0
MrDottt/CVE-2018-15473
Type: github • Created: 2021-09-14 23:20:52 UTC • Stars: 3
WildfootW/CVE-2018-15473_OpenSSH_7.7
Type: github • Created: 2020-12-09 15:09:31 UTC • Stars: 0
Sait-Nuri/CVE-2018-15473
Type: github • Created: 2020-11-29 17:36:11 UTC • Stars: 42
Dirty-Racoon/CVE-2018-15473-py3
Type: github • Created: 2020-11-27 12:25:41 UTC • Stars: 0
coollce/CVE-2018-15473_burte
Type: github • Created: 2020-11-26 05:17:08 UTC • Stars: 0
1stPeak/CVE-2018-15473
Type: github • Created: 2020-11-23 13:50:56 UTC • Stars: 0
LINYIKAI/CVE-2018-15473-exp
Type: github • Created: 2019-01-23 07:25:21 UTC • Stars: 1
r3dxpl0it/CVE-2018-15473
Type: github • Created: 2018-10-24 21:48:07 UTC • Stars: 16
pyperanger/CVE-2018-15473_exploit
Type: github • Created: 2018-10-08 20:59:04 UTC • Stars: 0
Rhynorater/CVE-2018-15473-Exploit
Type: github • Created: 2018-08-21 00:09:56 UTC • Stars: 523
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Added to KEVIntel