Language:
Severity: Medium
ID: 222159
File Name: unpatched_CVE_2018_20685.nasl
Version: 1.4
Type: local
Agent: unix
Family: Misc.
Published: 3/4/2025
Updated: 9/14/2025
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus
Risk Factor: Low
Score: 3.6
Risk Factor: Low
Base Score: 2.6
Temporal Score: 1.9
Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:N
CVSS Score Source: CVE-2018-20685
Risk Factor: Medium
Base Score: 5.3
Temporal Score: 4.6
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
CPE: p-cpe:/a:centos:centos:openssh-server-sysvinit, p-cpe:/a:redhat:enterprise_linux:pam_ssh_agent_auth, p-cpe:/a:canonical:ubuntu_linux:openssh-ssh1, p-cpe:/a:centos:centos:openssh-cavs, cpe:/o:canonical:ubuntu_linux:24.04:-:lts, p-cpe:/a:centos:centos:openssh-ldap, p-cpe:/a:centos:centos:openssh-server, cpe:/o:centos:centos:7, p-cpe:/a:redhat:enterprise_linux:openssh-server, cpe:/o:canonical:ubuntu_linux:22.04:-:lts, p-cpe:/a:centos:centos:openssh, cpe:/o:canonical:ubuntu_linux:18.04:-:lts, p-cpe:/a:redhat:enterprise_linux:openssh-keycat, p-cpe:/a:redhat:enterprise_linux:openssh-server-sysvinit, cpe:/o:redhat:enterprise_linux:7, p-cpe:/a:centos:centos:openssh-keycat, p-cpe:/a:redhat:enterprise_linux:openssh-clients, p-cpe:/a:centos:centos:openssh-clients, p-cpe:/a:redhat:enterprise_linux:openssh-ldap, p-cpe:/a:redhat:enterprise_linux:openssh-cavs, p-cpe:/a:redhat:enterprise_linux:openssh, p-cpe:/a:centos:centos:openssh-askpass, cpe:/o:canonical:ubuntu_linux:20.04:-:lts, p-cpe:/a:centos:centos:pam_ssh_agent_auth, p-cpe:/a:redhat:enterprise_linux:openssh-askpass
Required KB Items: Host/local_checks_enabled, Host/cpu, global_settings/vendor_unpatched, Host/OS/identifier
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 1/10/2019
CVE: CVE-2018-20685