Vulnerability Name:

CVE-2018-15599 (CCN-148629)

Assigned:2018-08-20
Published:2018-08-20
Updated:2020-12-30
Summary:The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2018-15599

Source: CCN
Type: Dropbear Mailing List, Mon Aug 20 17:50:11 AWST 2018
User enumeration in Dropbear 2018.76 and earlier

Source: MISC
Type: Mailing List, Third Party Advisory
http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002108.html

Source: MISC
Type: Mailing List, Third Party Advisory
http://lists.ucc.gu.uwa.edu.au/pipermail/dropbear/2018q3/002109.html

Source: XF
Type: UNKNOWN
dropbear-cve201815599-info-disc(148629)

Source: CCN
Type: dropbear GIT Repository
Dropbear

Source: MLIST
Type: Mailing List, Third Party Advisory
[debian-lts-announce] 20180827 [SECURITY] [DLA 1476-1] dropbear security update

Source: CONFIRM
Type: UNKNOWN
https://matt.ucc.asn.au/dropbear/CHANGES

Source: MISC
Type: Third Party Advisory
https://old.reddit.com/r/blackhat/comments/97ywnm/openssh_username_enumeration/e4e05n2/

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-15599

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:dropbear_ssh_project:dropbear_ssh:*:*:*:*:*:*:*:* (Version <= 2018.76)

  • Configuration CCN 1:
  • cpe:/a:dropbear_ssh_project:dropbear_ssh:2018.76:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:113438
    P
    signing-party-2.11-1.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:106839
    P
    signing-party-2.11-1.3 on GA media (Moderate)
    2021-10-01
    oval:com.ubuntu.disco:def:2018155990000000
    V
    CVE-2018-15599 on Ubuntu 19.04 (disco) - low.
    2018-08-21
    oval:com.ubuntu.bionic:def:2018155990000000
    V
    CVE-2018-15599 on Ubuntu 18.04 LTS (bionic) - low.
    2018-08-21
    oval:com.ubuntu.xenial:def:2018155990000000
    V
    CVE-2018-15599 on Ubuntu 16.04 LTS (xenial) - low.
    2018-08-21
    oval:com.ubuntu.bionic:def:201815599000
    V
    CVE-2018-15599 on Ubuntu 18.04 LTS (bionic) - low.
    2018-08-20
    oval:com.ubuntu.cosmic:def:2018155990000000
    V
    CVE-2018-15599 on Ubuntu 18.10 (cosmic) - low.
    2018-08-20
    oval:com.ubuntu.cosmic:def:201815599000
    V
    CVE-2018-15599 on Ubuntu 18.10 (cosmic) - low.
    2018-08-20
    oval:com.ubuntu.trusty:def:201815599000
    V
    CVE-2018-15599 on Ubuntu 14.04 LTS (trusty) - low.
    2018-08-20
    oval:com.ubuntu.xenial:def:201815599000
    V
    CVE-2018-15599 on Ubuntu 16.04 LTS (xenial) - low.
    2018-08-20
    BACK
    debian debian linux 8.0
    dropbear_ssh_project dropbear ssh *
    dropbear_project dropbear 2018.76