Paramiko records
4 published records for vendor paramiko.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-287 Improper Authentication1
- CWE-354 Improper Validation of Integrity Check Value1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-863 Incorrect Authorization1
The weakness classes this vendor ships most often: where to look.
CWEAll records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2023-48795Proof of concept | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypasssh · ssh · CWE-354 | Medium5.9 | — | 93.5% | Dec 18, 2023 |
47Plan | CVE-2018-7750Proof of concept | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.xparamiko · paramiko · CWE-287 | Critical9.8 | — | 27.1% | Mar 13, 2018 |
36Monitor | CVE-2018-1000805No exploit | Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can paramiko · paramiko · CWE-863 | High8.8 | — | 4.4% | Oct 8, 2018 |
24Monitor | CVE-2022-24302No exploit | In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized infparamiko · paramiko · CWE-362 | Medium5.9 | — | 2.1% | Mar 17, 2022 |
- CVE-2023-4879551Plan
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypas
MediumCVSS 5.9Proof of conceptEPSS 94%ssh · sshDec 18, 2023
- CVE-2018-775047Plan
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x
CriticalCVSS 9.8Proof of conceptEPSS 27%paramiko · paramikoMar 13, 2018
- CVE-2018-100080536Monitor
Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can
HighCVSS 8.8No exploitEPSS 4%paramiko · paramikoOct 8, 2018
- CVE-2022-2430224Monitor
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized inf
MediumCVSS 5.9No exploitEPSS 2%paramiko · paramikoMar 17, 2022