CVE-2016-6210 | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
- 🔗 access.redhat.com/errata/RHSA-2017:2563
- 🔗 www.securitytracker.com/id/1036319
- 🔗 seclists.org/fulldisclosure/2016/Jul/51
- 🔗 www.debian.org/security/2016/dsa-3626
- 🔗 www.exploit-db.com/exploits/40136/
- 🔗 www.exploit-db.com/exploits/40113/
- 🔗 www.openssh.com/txt/release-7.3
- 🔗 security.gentoo.org/glsa/201612-18
```Code``` unterstützt. Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | CVEs | Anteil |
|---|---|---|
| ≥90 % | 720 | 0,2 % |
| ≥50 % | 3.223 | 0,9 % |
| ≥10 % | 22.115 | 6,0 % |
| <10 % | 342.335 | 92,9 % |
CVE-2016-6210 | sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing difference between responses when a large password is provided.
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static password when the username does not exist, which allows remote attackers to enumerate users by leveraging the timing dif
Noch keine Analyse zu CVE-2016-6210
Sei der Erste: Einschätzung, Betroffenheit, Workaround oder PoC — mit Antworten im Thread.