SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-0777

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a…

MEDIUM 6.5EPSS 63.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 63.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

The resend_bytes function in roaming_common.c in the client in OpenSSH 5.x, 6.x, and 7.x before 7.1p2 allows remote servers to obtain sensitive information from process memory by requesting transmission of an entire buffer, as demonstrated by reading a private key.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
63.47% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
sophos/unified threat management software · oracle/linux · oracle/solaris · openbsd/openssh · hp/remote device access virtual customer access system · apple/mac os x
Source
secalert@redhat.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.