CVE-2018-15473

medium

Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

References

https://github.com/krishanpratapsingh/Pentesting-toolkit

https://github.com/bdalrhmnhamdalalm-jpg/CVE-2018-15473-User-Enumeration-

https://github.com/Athology0000/cve-lab

https://github.com/Guppss/VulnScan-Pro

https://github.com/daecayde/bloodhoundr

https://github.com/Ateebshaikh21/red-team-ai

https://github.com/daecayde/nightcrawler

https://github.com/ShacharLF/Network-Scanner

https://github.com/Ernest-Kosmatko/Netrecon

https://github.com/saqib-butt2/blackbox-pentesting-infsecos

https://github.com/Retr0wq/network-scanner

https://github.com/Sumeru-M/Automated_Vulnerability_scanner

https://github.com/Sombra-1/vulnmind

https://github.com/kaktus5454/CVE-2018-15473

https://github.com/kikechans/SSH-Enum-CVE-2018-15473

https://github.com/wtbacon/cve-2018-15473

https://github.com/jamalinux1/syntecxhub-cve-scanner

https://github.com/Remnant-DB/CVE-2018-15473

https://github.com/jubeenshah/CVE-2018-15473-Exploit

https://github.com/OhDamnn/Noregressh

https://github.com/anonymous121029034720384234234/py-network-scanner

https://github.com/Alph4Sec/ssh_enum_py

https://github.com/fujiokayu/nmap-nvd-script

https://github.com/rudra9603/vulnerability-scanner

https://github.com/makmour/open-ssh-user-enumeration

https://github.com/jlucas8/cve-test-scripts

https://github.com/0xNehru/ssh_Enum_vaild

https://github.com/OmarV4066/SSHEnumKL

https://github.com/krlabs/openssh-vulnerabilities

https://github.com/SUDORM0X/PoC-CVE-2018-15473

https://github.com/ryanalieh/openSSH-scanner

https://github.com/bigb0x/OpenSSH-Scanner

https://github.com/MahdiOsman/CVE-2018-15473-SNMPv1-2-Community-String-Vulnerability-Testing

https://github.com/bigb0x/SSH-Scanner

https://github.com/bigb0x/CVE-2024-6387

https://github.com/yZ1337/CVE-2018-15473

https://github.com/jtesta/ssh-audit

https://github.com/GaboLC98/userenum-CVE-2018-15473

https://github.com/sergiovks/SSH-User-Enum-Python3-CVE-2018-15473

https://github.com/thecyberworld/cve-exploits

https://github.com/wjl110/CVE-Master

https://github.com/Goldenmonkeyy/SSHusernameEnum

https://github.com/66quentin/shodan-CVE-2018-15473

https://github.com/MrDottt/CVE-2018-15473

https://github.com/An0nYm0u5101/enumpossible

https://github.com/Moon1705/easy_security

https://github.com/NHPT/SSH-account-enumeration-verification-script

https://github.com/trickster1103/-

https://github.com/secmode/enumpossible

https://github.com/LINYIKAI/CVE-2018-15473-exp

https://github.com/JoeBlackSecurity/SSHUsernameBruter-SSHUB

https://github.com/pyperanger/CVE-2018-15473_exploit

https://github.com/epi052/cve-2018-15473

https://github.com/Rhynorater/CVE-2018-15473-Exploit

https://github.com/gbonacini/opensshenum

https://github.com/trimstray/massh-enum

https://github.com/openbsd/src/commit/779974d35b4859c07bc3cb8a12c74b43b0a7d1e0

http://www.securitytracker.com/id/1041487

http://www.securityfocus.com/bid/105140

Details

Source: Mitre, NVD

Published: 2018-08-17

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 5.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Severity: Medium

EPSS

EPSS: 0.98631