Atleast if it's OpenSSH, you have to go way, way back to find a vulnerability that would actually allow remote access without any credentials. I think the most recent ones were the CRC32 deattack one (all servers with SSH1 enabled were vulnerable) and the integer overflow in PAM-related code (needed some non-standard but common config options). This was around 2001-2002 or so.

