Junglewise Threat Intelligence

CVE-2018-7749: PYSEC-2018-108 - The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other

CVE-2018-7749 · Severity: low · CVSS 3.1 · Published 2018-03-12

Technologies: asyncssh (PyPI). Vendors: PyPI.

Executive brief

The SSH server implementation of AsyncSSH before 1.12.1 does not properly check whether authentication is completed before processing other requests. A customized SSH client can simply skip the authentication step.

Affected products

  • PyPI asyncssh

Related threats