vendor:
by:
Mark E. Haase
6.8
CVSS
MEDIUM
SSHtranger Things
CWE
Product Name:
Affected Version From: OpenSSH 7.6p1
Affected Version To:
Patch Exists: NO
Related CWE: CVE-2019-6111, CVE-2019-6110
CPE:
Metasploit:
https://www.rapid7.com/db/vulnerabilities/suse-cve-2019-25017/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp3-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp8-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2019-7283/, https://www.rapid7.com/db/vulnerabilities/openbsd-openssh-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/redhat-openshift-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp2-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/amazon-linux-ami-2-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/redhat_linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/alpine-linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/huawei-euleros-2_0_sp5-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/ubuntu-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/oracle_linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/amazon_linux-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2019-6111/, https://www.rapid7.com/db/vulnerabilities/debian-cve-2019-6111/, https://www.rapid7.com/db/?q=CVE-2019-6111&type=&page=2, https://www.rapid7.com/db/?q=CVE-2019-6111&type=&page=2, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2019-6110/, https://www.rapid7.com/db/vulnerabilities/ibm-aix-cve-2019-6110/, https://www.rapid7.com/db/vulnerabilities/oracle-solaris-cve-2019-6110/, https://www.rapid7.com/db/vulnerabilities/openbsd-openssh-cve-2019-6110/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2019-6110/, https://www.rapid7.com/db/vulnerabilities/f5-big-ip-cve-2019-6110/
Platforms Tested: Ubuntu 18.04.1 LTS
2019
SSHtranger Things
We have nicknamed this "SSHtranger Things" because the bug is so old it could be exploited by an 8-bit Demogorgon. Tested on Python 3.6.7 and requires `paramiko` package.