← Back to browse · API

CVE-2018-15473

Severity
MEDIUM
CVSS
5.9
EPSS
0.98631
Risk score
58.12
CISA KEV
No
PoC
Yes
Published
2018-08-17
Modified
2025-12-17
First seen
2026-08-07
Aliases
EUVD-2018-7351, GHSA-C8QW-H3F6-FV63
Products
n/a:n/a n/a
Sources
github 52b21fcd72314938b59fa358|CVE-2018-15473
euvd EUVD-2018-7351

Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

References