CVE-2003-1562
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
sshd in OpenSSH 3.6.1p2 and earlier, when PermitRootLogin is disabled and using PAM keyboard-interactive authentication, does not insert a delay after a root login attempt with the correct password, which makes it easier for remote attackers to use timing differences to determine if the password step of a multi-step authentication is successful, a different vulnerability than CVE-2003-0190.
- CVSS 2.0
- 7.6 HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
- EPSS
- 5.57% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- openbsd/openssh
- Source
- cve@mitre.org
References
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747
- http://www.securityfocus.com/archive/1/320153
- http://www.securityfocus.com/archive/1/320302
- http://www.securityfocus.com/archive/1/320440
- http://www.securityfocus.com/bid/7482
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=248747
- http://www.securityfocus.com/archive/1/320153
- http://www.securityfocus.com/archive/1/320302
- http://www.securityfocus.com/archive/1/320440
- http://www.securityfocus.com/bid/7482
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.