Lucene search

K
cve[email protected]CVE-1999-1231
HistorySep 12, 2001 - 4:00 a.m.

CVE-1999-1231

2001-09-1204:00:00
web.nvd.nist.gov
18
cve-1999-1231
ssh 2.0.12
user account identification
remote attack
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.0%

ssh 2.0.12, and possibly other versions, allows valid user names to attempt to enter the correct password multiple times, but only prompts an invalid user name for a password once, which allows remote attackers to determine user account names on the server.

Affected configurations

NVD
Node
sshssh2Match2.0
OR
sshssh2Match2.0.1
OR
sshssh2Match2.0.2
OR
sshssh2Match2.0.3
OR
sshssh2Match2.0.4
OR
sshssh2Match2.0.5
OR
sshssh2Match2.0.6
OR
sshssh2Match2.0.7
OR
sshssh2Match2.0.8
OR
sshssh2Match2.0.9
OR
sshssh2Match2.0.10
OR
sshssh2Match2.0.11
OR
sshssh2Match2.0.12

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

62.0%

Related for CVE-1999-1231