CVE-2018-15473 - CVE House
Back to Database
Status published Unknown CVE-2018-15473

OpenSSH through 7.7 is prone to a user enumeration vulnerability...

Vulnerability Description

OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-15473

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

openssh, debian linux, enterprise linux desktop, enterprise linux server, enterprise linux workstation, ubuntu linux, cn1610 firmware, aff baseboard management controller, cloud backup, data ontap edge, fas baseboard management controller, oncommand unified manager, ontap select deploy, service processor, steelstore cloud integrated storage, virtual storage console, clustered data ontap, data ontap, vasa provider, storage replication adapter, sun zfs storage appliance kit, scalance x204rna firmware
Vulnerable Versions:
0, 8.0, 9.0, 6.0, 7.0, 14.04, 16.04, 18.04, 9.4, 7.2, 8.8.6

Timeline

Official Publish: August 17th, 2018
Last Modified: December 17th, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.