CVE-2016-6210
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 88.9%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 88.94% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- openbsd/openssh
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2016/Jul/51Mailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3626
- http://www.securityfocus.com/bid/91812Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036319
- https://access.redhat.com/errata/RHSA-2017:2029
- https://access.redhat.com/errata/RHSA-2017:2563
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://security.gentoo.org/glsa/201612-18
- https://security.netapp.com/advisory/ntap-20190206-0001/
- https://www.exploit-db.com/exploits/40113/
- https://www.exploit-db.com/exploits/40136/
- https://www.openssh.com/txt/release-7.3Release Notes, Vendor Advisory
- http://seclists.org/fulldisclosure/2016/Jul/51Mailing List, Third Party Advisory
- http://www.debian.org/security/2016/dsa-3626
- http://www.securityfocus.com/bid/91812Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1036319
- https://access.redhat.com/errata/RHSA-2017:2029
- https://access.redhat.com/errata/RHSA-2017:2563
- https://cert-portal.siemens.com/productcert/pdf/ssa-412672.pdf
- https://security.gentoo.org/glsa/201612-18
- https://security.netapp.com/advisory/ntap-20190206-0001/
- https://www.exploit-db.com/exploits/40113/
- https://www.exploit-db.com/exploits/40136/
- https://www.openssh.com/txt/release-7.3Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.